Summary
- Kanishka Narayan said AI model testing remains useful but should be supplemented by stronger defensive measures.
- The minister highlighted cyber security, biological risks, and systems acting beyond intended instructions among current concerns.
- The intervention broadens the UK AI-security debate from evaluating model capability towards controls that operate after systems are deployed.
UK AI minister Kanishka Narayan has argued that testing advanced artificial-intelligence models is insufficient on its own, placing greater emphasis on operational defences as increasingly capable systems move from controlled evaluations into organisations and infrastructure.
Speaking during the Labour Party conference, Narayan said the UK should continue evaluating advanced models while also preparing for risks that cannot be contained through testing before deployment. He identified cyber security, the potential use of AI in biological threats, and systems behaving beyond the tasks humans intended among areas requiring attention.
His intervention does not amount to an abandonment of model evaluation, which remains a central function of the UK AI Security Institute. Instead, it widens the security problem from identifying dangerous capabilities in advance towards controlling what systems can access, what actions they can take, and how organisations respond when safeguards fail during real-world use.
The distinction becomes more important as AI products move from conversational assistants towards agents capable of operating software, calling external services, writing code, and making changes across connected systems. A model can perform acceptably during an evaluation while still becoming dangerous if it is later given excessive permissions, sensitive data, or an operating environment whose failure modes were absent from testing.
Evaluation catches only part of the risk
The UK has invested in the principle that governments should be able to test frontier models independently rather than relying entirely on assessments supplied by developers. The AI Security Institute has consequently built technical capacity around model evaluations, cyber capabilities, safeguards, and other areas of advanced-AI research.
That work remains relevant because model capability determines which kinds of harm are technically possible. A system incapable of developing useful malware, manipulating laboratory information, or operating autonomously presents a different risk profile from one that can perform those tasks reliably.
Capability testing does not, however, determine how a model will be configured inside an organisation. Enterprise systems introduce identities, access permissions, APIs, databases, cloud accounts, employee devices, approval processes, and external suppliers, creating a much larger attack surface than the model itself.
An AI agent given access to corporate email and a customer database, for example, creates risks that depend on how its permissions have been designed as much as on the underlying model. Prompt injection, compromised credentials, bad instructions, software vulnerabilities, or an agent pursuing a legitimate objective too aggressively can all produce failures even where the model has passed pre-deployment testing.
Narayan’s comments therefore bring AI security closer to established operational-security practice, where prevention is combined with containment, monitoring, access control, incident response, and recovery. His position is that testing remains useful but should not be treated as a complete defence.
The government has also been reshaping the institutions around that work. Dr Jade Leung was appointed vice-chair of the AI Security Institute and security adviser to the AI Taskforce this month, linking technical research with security work inside central government.
Deployment changes the security problem
The operational question becomes harder as AI systems gain greater autonomy. Conventional software normally follows predetermined instructions written by developers, whereas an agent may decide which tools to use and which intermediate actions to take while pursuing a broader objective.
That flexibility creates much of the commercial value promised by agentic AI because organisations want software that can complete workflows rather than merely generate suggestions. It also makes static security assumptions less reliable, particularly when an agent interacts with systems developed by several suppliers.
Traditional controls provide part of the answer. Least-privilege access can restrict what an agent is allowed to reach, separate identities can distinguish autonomous actions from those taken by employees, and logging can preserve a record of decisions and tool use. More specialised approaches are emerging around sandboxes, runtime policy enforcement, and independent monitoring capable of stopping an agent when it crosses an authorised boundary.
Those controls introduce implementation trade-offs because every additional safeguard can affect speed, cost, and functionality. Organisations will have to decide which actions can be performed autonomously, which require human approval, and which systems should remain inaccessible to an AI agent regardless of its apparent capability.
The same problem applies at national level. Governments can test the most advanced models available to them, but many damaging uses will occur through ordinary commercial systems, open models, or combinations of software that cannot be assessed centrally before every deployment.
Narayan also said the UK intends to use its G20 presidency next year to convene international discussion around AI risk. In the nearer term, however, the policy problem is more practical: as AI systems are connected to government, business, and critical infrastructure, security has to account not only for what a model can do in a laboratory but for what happens when an imperfect system is given permission to act.












