09/02/2026 | Press release | Distributed by Public on 09/02/2026 05:11
One of the practical challenges in applying frontier AI to cyber defence is deciding how much organisational information the model and harness should be allowed to access.
Model effectiveness is highly dependent on the quality and relevance of organisational context. Relevant inputs can include source code, asset and environment information, security architecture, control data and other contextual material.
However, deciding what information can be safely provided to FAI models and harnesses remains a central risk management question. Differentiated approaches may be relevant for classification, supplier assurance, data access and exclusions, including limiting repositories, sensitive intellectual property or higher-risk business areas from ingestion. The engineering challenge is to provide enough context to generate actionable findings while reducing unnecessary exposure of sensitive information. Relevant considerations include confidentiality, data protection, supplier assurance, information-handling restrictions, and potential misuse if a powerful model or harness were compromised.
Direct deployment into production networks is generally regarded as higher risk, particularly where cyber guardrails are removed or where the model could interact with live systems. Firms are therefore exploring isolated, sandboxed, production-like or non-production environments to obtain security benefit while reducing operational and misuse risks.
A clearer treatment of data access can help define which repositories, assets, environments and data classes are in scope, restricted or excluded. Useful distinctions can include source code as a production artefact, production networks, production-like test environments, externally facing perimeter testing and human-executed attack simulation. These distinctions can help separate access to source code or production artefacts from access to live production environments.
The overall challenge is to provide enough information for frontier AI to produce useful cybersecurity outcomes while reducing unnecessary exposure of sensitive systems, data and intellectual property.