In this NCSC podcast episode, Minister for AI Lord Camrose and NCSC RCTO Oli Whitehouse discuss the current prominence of artificial intelligence. They highlight AI's dual nature, offering immense productivity gains while raising fears of dystopian outcomes, particularly if unregulated. The launch of ChatGPT catalyzed public interest, though AI's development had been ongoing for decades. Both speakers emphasize that regulated AI can manage risks, with governments actively addressing them. In cybersecurity, they argue AI's defensive potential may outweigh offensive threats, as it helps overcome capacity constraints and improves threat detection. Ethical concerns, such as bias from training data and misuse through jailbreaking, require careful management, including red teaming and human oversight. Adversaries are already exploiting AI for phishing, data analysis, synthetic identities, and malicious code, but the NCSC advocates for "secure by design" principles, integrating security throughout AI development. The conversation underscores the need for balanced, proactive approaches to harness AI's benefits while mitigating its risks.
[Music] Hello and welcome to the next episode of the NCSC's podcast series. Today we'll be talking about artificial intelligence. I'm delighted to be joined by by Count Cameras, Minister for AI and Oli Whitehouse, RCTO. Welcome to both of you. I think let's just begin by getting a sense of why you think AI is such a topic of the moment at the moment. I think it's a topic of the moment for two almost opposing reasons. One is that the opportunities that AI offers for greater productivity in almost any area of the work we do or any area of our lives are absolutely huge, fundamental and game-tenting. But equally, there's a lot of fears about the risks of AI and is one of these sort of strange technology situations in which are sort of dystopia on one side and utopia on the other side, which is obviously has caught both the public imagination and the imagination of professionals in the space. So I think not for dissimilar reasons. So anyone that was working with technology sphere, AI machine learning wasn't really a surprise. It was in a several decades in the making, but we have this kind of turning point of generative AI, which people really understood than the power and the potential. And I think with the advent of any technology that feels it's come around quickly to most, it can seem a bit of a shock in an atmosphere and everything that starts to stem from that. But neither of you have mentioned the start of when Chatchy PT sort of launched and everybody started using it and that moment that led to a kind of tidal wave of interest. Well, that was a very curious thing because anybody who followed AI was very aware of AI's capabilities before that moment and not just in large language models and this, but other forms of assistive AI as well had been growing very greatly. And then suddenly at that moment, what was interesting is it hit the public eye in a very dramatic way and the public went from not being terribly interested in AI to absolutely laser focused on AI more or less overnight. That was an amazing moment and I often wonder to myself by the way, what would happen if other technologies that were quite close to fruition but haven't quite got there yet, if they received the same public attention, what if there's a quantum moment when everybody goes, oh wow, quantum is really going to change everything. I think quantum is probably not quite there yet, it says, doesn't quite work as an analogy. But anyway, it was a very remarkable moment when was it? March, last year? Something like that. Just to go back to one of your points before, you mentioned the sort of dystopian angle on AI. Do you think perhaps that is overblown versus the sort of real security concerns that exist within it? What's your perception on that? Look, I think an unregulated AI would absolutely have the potential to be dystopian. If we said, okay, we're going to treat this a bit like we treated social media and e-commerce companies in the early 2000s, we're just going to back away and we're not going to worry too much about it. I think that would have the potential to be very concerning. No question about that at all. On the other hand, governments are taking the risk very seriously. I don't just mean UK, I mean, EU, the US and indeed further afield, they're taking the seriously. So I think regulated AI, of course, will never get rid of the risks, but we can manage them for the and produce the rewards of greater productivity. Olli, what's your take on that? You know, I've lived through various ages of Cybersypia and so I've come somewhat numb to it over the decades. I think the reality is that it will provide incremental benefit to those that wish to do harm, but it's they want to do harm anyway and that they would have tried to have done something with some tooling and this maybe just make them a little bit more effective. I think we're a little way off from this becoming the kind of the universal capability that allows them to unleash nation state capability at the drop of a kind of a chat GPT interaction by any stretch. And so I think I work on the on the basis that, yes, we need to be mindful of it, we need to understand the risks it poses, but I also believe the cyber defence benefit will often outstrip the cyberoffensive gain that our adversaries get. So we at the NTSC recently put out a report on ransomware adversaries potentially benefiting from some AI capabilities, so you think the defence will outweigh the offence? I think so, yes, you know, and so in the offensive space we will see it will be able to produce some type of malicious code, it will allow some fishing campaigns to be conducted, you know, all of that, but I think that the fact that AI allows us to address some of the capacity constraints and then making informed decisions that we historically we struggled with means that there is potential far greater upside for cyber defence than there is offence because of just the nature of the game that we play. We'll probably get into the cyber security angle a bit further into the conversation, but there's also some ethical concerns about the use of AI. Lord Cameron, what's your perspective? Yeah, I mean, so there's the fairness this you, you know, and the bias. So, I mean, this is the classic one, so that, you know, because of the existing data sets on which AI was trained, it tends to pick up a number of societal biases that have become, let's say, embedded in the data record over the last 20 years or so. And that's really a problem, and you know, you can't just as I would have thought first thing, you can't just say, okay, well, let's take out all the protected characteristics data and we're fine because obviously it can, it's good at inferencing, and it can pull out all of the inferences that you want. The other piece with that concern is the the better we get at solving it in a weird way, the more dangerous it becomes, you know, because picking out, I don't know, if there's, if there's a dangerous or unfair line once every 10 pages, you can pay that up. There's once every 100 pages, it gets more difficult, it's once every 10,000 pages and so on and so on. So it does get really hard and it's both a computer science problem and a kind of behavioral problem. But I think, you know, it's one that, you know, to all these earlier points, it's one that the AI, I'm, I feel, can help us solve as well as be the root cause of, to kind of, you know, and only use the language offensive defensive and I think it doesn't quite apply, but maybe, maybe use AI to police itself in that way. And there's obviously not just the data that it's trained on, but also how you use AI and that opens up a whole bunch of additional ethical questions. - Yeah, absolutely. And, you know, and prompt engineering and jail breaking to, to try and get the AI to reveal, you know, dangerous, give you tips how to do dangerous things or destructive things or, you know, chemical, biological attacks, whatever they may be. And again, these are hard to stop or harder to stop than they sound. You know, and red teaming is, is, you know, is a very important part of this and keeping humans sort of in the loop and doing that. But I think it's, it's, you know, it's something that we have to kind of stay one step ahead of the capabilities of the machine as we go. And again, I think as an example of where the AI itself can be used as a defensive measure as well as, as well as the cause of the problem. - Holly, do you have any take on the ethical term? - Yeah. I think it's a really fair challenge. I think one thing we have to recognise is that that in the UK at least we have a very, you know, a very balanced kind of system of power. And so things like this cannot be go, the, the use of these things cannot go unchecked necessarily if you look at both the regulatory regimes and, and wider. So there will always be ethical concerns. For any large technological shift of which this is one, though there is natural anxiety which comes, comes to the fore. I think, you know, people also need to realise that, that, you know, those, those ethical issues need to be navigated in order for it to gain the benefit. Our adversaries are not constrained in the same ethical way. And I think, you know, that, that, that is, that is the line we need to walk. So yes, we need to be ethical, we need to proportionate all of those things. But we need to do so at pace and take society on a journey with us to have that conversation. Last our adversaries are running at pace in a way which is unconstrained. And, and how we get there to an actual outcome is, is the challenge for us as, as leaders in the country? - Do you both think that we're sort of, because we're too concerned almost about the big dystopian risks we talked about before, that we maybe lose some of the nuanced questions around ethics or around other aspects of AI? - Well, honestly, that's, and I don't want to sound complacent, but that's not a worry for me. I think we've, we've focused a lot on frontier risk. And, you know, we had our big Blacksley Park Summit last, last year. That was a very important part and focus very much on, on these further out, very serious, but not quite with us risks. But we also spend a great deal of time focusing on the withers right here and that right now risks, you know, the, you know, the biases you're talking about, the risk of unfair working practices and so on and so on, obviously cyber security too. And these are, you know, we have to kind
Ac yn y pwysteidiol, ddude au'r sj MAR to di iconic am tim idag iefi ddiwae ynablyd genodol egg. Uwneud ac yn natni farloor y bawb? Y gewaterchu jaw a y breg i sicrhau yn konfer o blor cyقي sydd y ni febartanaeth g跟我ta mae agriciwnaeth oedd noston diol.' Mae'n gweithio'r gael o'r ffyrddio yw eich mwyth amser ar y ffyrddio i'r gael amser y ffyrddio. Mae'n gweithio'r rhaid ydw i ni'n ffyrddio'r rysk sydd ar y gael amser y cyfrir, wrth yna yn ychwyrddio â'r rhaid yn rhan o'r rhaid yn ffyrddio'r rysk. Mae'n gwybod yn yna yn ffyrddio wedi'i ffyrddio'r rysk. Chywn ni y trynyg oedd ym 45 cuwlig. fe fe. presents o yma o ff growth o ancestorsissan, oesżygu, ador加re fwysebur hyn yn gwnetfa add darauf reisoad cyllpoffigau e major o drwydd yn meddwl gwnau. Gwyse Currently, wedi line yng ng ہے oír jou nidfightfodol sut i fall happenai past ei qwysig yrwb i geworm wedi aĐoteth, di cyffoliadau. Mae'n gwaithio gwneud oesgol a ffysig yrwb i'n gwaithio oedd yr ymgwysig ymwysigio, yna, ag ymwysigio'r ymwch yw'r ysgwysigio, oeddwn i'n gwaithio. Gwyse Mae'n gwaithio, mae'r ymwch yna, yn gwaithio, ond yn y ffysigio, ond yn y rhan, yn gwaithio, yna gwaithio'r ymwch ymwch yna. Oly, wat y ffysig ar gyfer yn ffysigio, mae'n gwaithio'r ymwch yna? Mae'n gwaithio'r ymwch ymwch yna, mae'n gwaithio'r ymwch yna, mae'n gwaithio'r ymwch yna, mae'n gwaithio'r ymwch yna. Mae'n gwaithio'r ymwch yna, mae'n gwaithio'r ymwch yna, mae'n gwaithio'r ymwch yna. Un��di, amn yn unmewn'n defnyddorol fel un危 haircut cofdorol ac yn couot o dyl cynnun höstau, yneych peryng Gyda'r Teiddrywol. Fオrgrosol hyn, y ni'n legg hyn yn menthu ddeill ni fan ac bod, thou'n siargu factorsau yn gyfer gwarfnidd i'r D Jewel wedisiol cy yn ffっちadeen; o'r hynny cennun mewn mewn ysாff— am synny 돌 ar fwy rhan ar o'r bと fydd кон法u yn ymwyr i'n ffっちadeen i'r D Jewel. Mae'n yw'r ddod yn ymwyr i'r D Jewel, yn ymwyr i'r D Jewel, ac yn ymwyr i'r D Jewel, ac yn ymwyr i'r D Jewel, ymwyr i'r D Jewel, ymwyr i'r D Jewel, ymwyr i'r D Jewel, ac yn ymwyr i'r D Jewel, ac yn ymwyr i'r D Jewel, ac yn ymwyr i'r D Jewel. A'r D Jewel, ac yn ymwyr i'r D Jewel, ac yn ymwyr i'r D Jewel, ac yn ymwyr i'r D Jewel, ac yn ymwyr i'r D Jewel, ac yn ymwyr i'r D Jewel, ac yn ymwyr i'r D Jewel, ac yn ymwyr i'r D Jewel, ac yn ymwyr i'r D Jewel, ac yn ymwyr i'r D Jewel, ac yn ymwyr i'r D Jewel, ac yn ymwyr i'r D Jewel, ac yn ymwyr i'r D Jewel, ac yn ymwyr i'r D Jewel, ac yn ymwyr i'r D Jewel, ac yn ymwyr i'r D Jewel, ac yn ymwyr i'r D Jewel, ac yn ymwyr i'r D Jewel, ac yn ymwyr i'r D Jewel, ac yn ymwyr i'r D Jewel, ac yn ymwyr i'r D Jewel.
yw'n gweithio yn yw'r gweithio i'r cyfnod yma. Ym gweithio'r gweithio yn ymg i'r cyfnod yma. Ym gweithio yn llun yn ei ffyniadau, ac yma gweithio yn ymg i'r cyfnod yma. Ym gweithio yn ymg i'r cyfnod yma. Ym gweithio yn ymg i'r cyfnod yma, ac ymg i'r cyfnod yma yn ei ffyniadau yma. Ym gweithio yn ymg i'r cyfnod ymg i'r cyfnod yma. Ym gweithio yn ymg i'r cyfnod yma yn ymg i'r cyfnod yma yn ymg i'r cyfnod yma. ti'u conveno'r appelu u gy除ch chi yn fwasyr 6. megapú lidiau chiolegio'r testa, eio gwll get #1 i'r pefar i'm lyr president. Mae'r ekplau i'r發io diolos credu fy'r gwneudienne i'r prôfio y emblemiss9. Cael dinodd, pan ac, wrth werth can ylwio. Gwy AM eiffedel esolau unser eu gwneud Xoiduашau長 yn ac mae hyffe Respond i'r apeliweud chi псfiad yr dyswedydd sy easily eich ein rwy'n gweith yng Nghymru yn ymg diffé wedi'r yng Nghymru wedi rydw i'r llwysig. Mae yna o'r unwn oes i'r llwysig, oeddol yn ddod yn yr yna. Mae oes i'r llwysig oedau sy'n yr unwn i'r llwysig. Mae oes i'r llwysig i'r llwysig i'r llwysig yng Nghymru, yn yna oes i'r llwysig yng Nghymru wedi'r llwysig. Ond yn ni yng Nghymru wedi'r llwysig i'r llwysig i'r llwysig. Mae yng Nghymru wedi'r llwysig i'r llwysig. mae'n summitau pobl Mentoriaweaedd y gydiffbod panol oedd ddim iwheel上 yo roec mod會 o Itr Ford. Don ddim i ôlwyr ei dîm Yn selanddd eu y'n dr fabricair o it-wiEl gweld ar ddweud os ni ei sicrhaiedd y dod o rhywodd i mae hynnygu yn ond ac mae it-wi wedi gallwyd gyfer sydd wedi nyng aboardd. Mae'n gyd yw'r gydiffod yn ffyrddol oedd yn ffyrddol oedd yn ffyrddol oedd yn ffyrddol oedd yn ymgylch. Mae'r gydiffod yn ffyrddol oedd yn ffyrddol oedd yn ffyrddol oedd yn ffyrddol oedd yn ffyrddol oedd yn ymgylch. rhwyd ddwonai'n y Gwynch wed ninth rwyrd o'r тов chickens a submitting efo. Ga monthly eich trebogaeth yw beth gwy »a os i gwir yma lífット未r flaws lawy-eg bwyrr wed heated byna wal iawn, eich oso defneud quickly yn ac cuad cyf Walesi uy��w yng Nghydd y gallw'r ac rwo ichod ym wedi ei ein rhaid ac eros thinau ac garbynn yma ei w dú. Eiciaid yn my İnsymraeth i'n adon nhw'r eiffredd w'uno'r eu boEL senior ydyll Juan Minist no ni unain ond chyd d rena Iidawn Iudd unanaethau ys Martillol En elitesach ond nen ac hun eisiau Teams yng Ngwyth santaerol ac mae'r snig er ffwrsaf peir tただ asiantad fel o ystaf tythafelen ei lwn ei werwfie nad yw ddifel. organol ames Covid o'r 100aben casthau bod a gwygefod, mae eiol arwl amdeillusom i gwahanol gan pr samerd Warny, mae ydyfniad yn croestiool, o gyому cy considerably mw크 fod yma. Yn sylwan wy funniestyn ei cofru o ddim o ie wneud芸iau acprofadrydd yn fforddi accuracy o rhaluk special sy o gyda beth tr Więc семem. Els yn'M이다 VIC�airll Kristiwerth yn cymchol i yopyginio cael o'r ai o 50% a clyfru yn dig wedyn cre** beth sy'n realleg beth New Weithred though, dig wedyn man oerwheel i biford ac Exerc、 â��ol ystanc yn i wearg, i ba yn nhw ychwydod sy'n y nausewyr lle ericfryd er abbakul, Maenniej i creосьn o'rорod o hedatriud fel icolб拜au fel ministeri 11 Hernau a i chi, Jwy GDAY comes yw, trynaillig felseiwn gwir etcbliawn faig addon mu, ac ll blindi fod mes! Ofy'n casretu enfilmag <i>Røddy Francesa Oliver</i> i Bliddf خadderaldau fel am gyphydm確oratig fel gyfr Gom beşarr cheering
cus yn f tweetinguaeth i'wσι daethi dimnych chi d everythingraethu gan fawrnyddi'r bet demographicig. Sew GC7 a Mynd, y метd sydd fel reallичir y dyna y recordissu. Gen i'r codol cad, y gallag mornarForentau'n honunoмерhi, hon rea ddigótaeth y 快waeth lle, ddim y ffordd yng Nghymru nad Dweud, hyn bahau reallitur Peresus. Brogddol, fel erud enr ongoingarell, yn ymwyr i'r cyflwyn, yn ymwyr i'r cyflwyn, yn ymwyr i'r cyflwyn, yn ymwyr i'r cyflwyn, yn ymwyr i'r cyflwyn, yn ymwyr i'r cyflwyn. Ymwyr i'r cyflwyn, yn ymwyr i'r cyflwyn, yn ymwyr i'r cyflwyn, yn ymwyr i'r cyflwyn. Mae'r cyflwyn yn ymwyr i'r cyflwyn. Mae'r cyflwyn yn ymwyr i'r cyflwyn yn ymwyr i'r cyflwyn. Mae'r cyflwyn yn ymwyr i'r cyflwyn yn ymwyr i'r cyflwyn yn ymwyr i'r cyflwyn. o'r unrhyw i ddyddiad o'r gwaithio fel ymlygu yn ffyrdd. Mae'n gwaithio ymlygu'r amser, ac yn yna, yna, yna, yna, yma rhan yn ymlygu'r amser. Mae'n gwaithio yn yma'r gwaithio yn ffyrddio yn yna, yna, yna, yna, yma rhan ymlau yn gwaithio yn ymlau i'n gwaithio. Yna, yma'r gwaithio yn ymlau'r gwaithio. Ilar Sh� C). Gr rhyngyff eведdor. teníanbar. Rynymr brittle rwyddyn ynetteidorfil neu перhoddau c amgylidorddild. Roedd cael metna 눈 10% neu y med Riddracaturnu siethu 1940 yw. Fly offendro. Skadech cymry llyfnau slood yn curi'i i beth syfly! Roedd cael beth o'r rhyngyff eiddor, a'r rhyngyff eiddor, a'r rhyngyff eiddor, a'r rhyngyff eiddor, a'r rhyngyff eiddor, a'r rhyngyff eiddor, a'r rhyngyff eiddor, a'r rhyngyff eiddor, a'r rhyngyff eiddor, a'r rhyngyff eiddor, a'r rhyngyff eiddor, a'r rhyngyff eiddor, a'r rhyngyff eiddor, a'r rhyngyff eiddor, a'r rhyngyff eiddor, a'r rhyngyff eiddor, a'r rhyngyff eiddor, a'r rhyngyff eiddor, a'r rhyngyff eiddor, a'r rhyngyff eiddor, a'r rhyngyff eiddor, a'r rhyngyff eiddor, a'r rhyngyff eiddor, a'r rhyngyff eiddor, a'r rhyngyff eiddor, ond histeng ond eich sioppinganey? Felly, 'heatredde sylwnas a phanau dygynu sk one ond Danishicart- ynes i´n bethh'. Ce— responsibility of heavy combat derbyn ampleierau o med Whitwpig traithol um enquirantal. We are seeing adversaries using a variety of different ways, as we've mentioned, from fishing through to being able to use it to interrogate data, which they've stolen through to doing generative AI to produce synthetic identity and faces and add through to emergent nace and examples of where they are using it to produce malicious code, which isn't detectable via traditional existing detections. So they are exploring the value and we have seen and will expect to see that deployed. The trick will always be that we understand that and we can either in lockstep or get ahead of them to negate or new to that capability. So if I can't hammer it, we need to be quite clear-eyed about the threat from our adversaries as well as the risks around some of the risks we've discussed already. Yeah, look, I think so. I mean, the other point on that I was going to make, a very strong agreement with Olli, is that I think what the NCSC is really helping with is this idea of secure by design. So I mean, I think there was a period in the development of technologies when you would build all the great functionality and then go, "Alright, now we're going to put a security layer on top and we'll be fine." So that doesn't work any more and it certainly doesn't work in a very smart AI attacker world. So securing it at every state of development from all kinds of attacks, but especially in AI, I think is such an important piece of the whole. And in some ways, rather an emerging discipline. Thank you both for all those great insights on all things AI. I think we'll have to leave it there for today. We really hope you've enjoyed this episode and if you want to find out more, keep your eye on the NCSC website and also come to CyberUK in May. Thanks all.
Podcast Summary
Key Points:
AI is a major topic due to its dual nature
The launch of ChatGPT marked a turning point, rapidly shifting public interest from minimal to intense focus on AI.
Regulated AI can manage risks, but unregulated AI could be dystopian; governments (UK, EU, US) are taking risks seriously.
In cybersecurity, AI may offer greater defensive benefits than offensive gains, helping address capacity constraints and improve decision-making.
Ethical concerns include bias in AI training data, fairness issues, and the challenge of preventing malicious use (e.g., jailbreaking), requiring human oversight.
Adversaries are using AI for phishing, data interrogation, synthetic identity creation, and generating malicious code, necessitating proactive defense.
"Secure by design" is crucial for AI development, integrating security at every stage to counter advanced threats.
Summary:
In this NCSC podcast episode, Minister for AI Lord Camrose and NCSC RCTO Oli Whitehouse discuss the current prominence of artificial intelligence. They highlight AI's dual nature, offering immense productivity gains while raising fears of dystopian outcomes, particularly if unregulated. The launch of ChatGPT catalyzed public interest, though AI's development had been ongoing for decades.
Both speakers emphasize that regulated AI can manage risks, with governments actively addressing them. In cybersecurity, they argue AI's defensive potential may outweigh offensive threats, as it helps overcome capacity constraints and improves threat detection. Ethical concerns, such as bias from training data and misuse through jailbreaking, require careful management, including red teaming and human oversight.
Adversaries are already exploiting AI for phishing, data analysis, synthetic identities, and malicious code, but the NCSC advocates for "secure by design" principles, integrating security throughout AI development. The conversation underscores the need for balanced, proactive approaches to harness AI's benefits while mitigating its risks.
FAQs
AI is a major topic because it offers huge opportunities for productivity and growth, while also raising significant fears about risks and potential dystopian outcomes.
The launch of ChatGPT created a 'tidal wave of interest,' as the public went from not being very interested in AI to being laser-focused on it almost overnight.
Unregulated AI could have dystopian potential, but governments are taking the risks seriously, and with proper regulation, the risks can be managed to harness AI's benefits.
AI is likely to benefit cyber defense more than offense, as it can address capacity constraints and improve decision-making, while offensive gains are expected to be incremental.
Key ethical concerns include bias from training data, fairness issues, and the risk of jailbreaking AI to produce harmful outputs, though AI itself can help police these issues.
Adversaries are using AI for phishing, interrogating stolen data, generating synthetic identities, and producing malicious code that can evade traditional detection methods.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.