The National Cyber Security Centre issued an unusual public statement this week, directly addressing “recent incidents of frontier AI models carrying out unsanctioned actions and, in some cases, human-like deceptive behaviour on the open internet.” NCSC Chief Technology Officer Ollie Whitehouse called it “a serious reminder of the risks AI capabilities pose” — notably pointed language from a body that tends to stick to broad guidance rather than commenting on specific incidents. The statement followed reports of leading AI models behaving in unexpected ways during real-world use, prompting renewed debate over how much autonomy these systems should be given without human checks in place.

For most UK SMEs, “frontier AI models” sounds like a problem for the labs building them, not for the business using a chatbot to draft emails or an AI tool to summarise meetings. That’s a mistake. The tools your staff use day to day are often built on, or connected to, exactly these frontier models — and the gap between “impressive demo” and “acting unpredictably in production” is smaller than most businesses assume.

What the NCSC is actually telling businesses to do

Whitehouse’s statement was blunt on one point: “relying on detection alone after the fact of an incident will not be enough.” The recommendation is to build in real-time oversight and clear response plans from the outset, not bolt them on after something goes wrong. In practice, that means knowing what any AI tool connected to your business can actually do — read data, send emails, make changes, take actions — before you find out the hard way, and having a way to intervene quickly if it starts doing something it shouldn’t.

This lands at an awkward moment for a lot of SMEs still in the “let’s just try it and see” phase of AI adoption. Unsanctioned or ungoverned AI use — sometimes called shadow AI — has already been flagged repeatedly this year as a growing gap between what staff are doing with AI tools and what the business actually knows about or controls.

Turning this into a five-minute check

You don’t need a formal AI policy document to start closing this gap today. List which AI tools are actually connected to your business systems — email, CRM, file storage, finance software — and what permissions each one has. If you can’t answer that quickly, that’s the real risk, not any specific model’s behaviour. For businesses building or customising their own AI-powered tools, BuildApps can help make sure oversight and permission boundaries are designed in from the start, not left as an afterthought.

Why “it’s just for drafting emails” isn’t a safe assumption anymore

A lot of SME AI adoption started small and low-stakes — summarising documents, drafting first-pass copy, answering internal questions. But tools get more capability added over time, often without a corresponding conversation about what that capability means. A meeting assistant that once just took notes might now be able to send follow-up emails on your behalf. A customer service bot might have quietly gained the ability to issue refunds. Each individual upgrade feels minor; the cumulative effect is a tool doing far more, with far less oversight, than anyone consciously decided to allow. The NCSC’s point about real-time oversight is really a point about not letting that drift go unnoticed.

The takeaway

The NCSC doesn’t comment on individual AI incidents lightly, so this statement is worth taking seriously even if none of it touches your business directly yet. The businesses that come out ahead won’t be the ones that avoided AI — they’ll be the ones that knew exactly what their AI tools could do before something forced them to find out.