Why do promising AI pilots struggle to reach UK security teams?
A 28 September CETaS report examines public–private AI partnerships using 22 expert interviews and two focus groups. Its recommendations concern procurement and coordination, not proven operational gains.
Editorial responsibility: The Impact of AI Editorial Desk · Report a factual concern
At a glance
- 1Expert interviews identify organisational barriers, not a measured adoption rate.
- 2A proposed coordination body is not yet evidence of operational improvement.
Living evidence record
Impact record IAI-1PBED90
Evidence stage
Announced
Confidence
Developing
Reporting basis
Source analysis
Independent support
Not yet
Record status
Monitoring
Last checked
30 September 2026
Source trail
1 direct source across 1 source type.
People impact
Documented in this record.
Uncertainty
Limits and next checks are explicit.
Stages describe the evidence available—not whether a technology is good or bad. See the public method.
Single-source reporting disclosure
This record analyses one direct source. It can establish what CETaS / The Alan Turing Institute published or reported, but it is not independent corroboration of every performance claim or predicted outcome. The confidence label will change only when broader evidence is added.
The evidence behind the recommendations
CETaS at The Alan Turing Institute published a study of UK national-security AI partnerships on 28 September 2026. Natasha Karner, Anna Knack, Mackenzie Jorgensen and Carolyn Ashurst draw on a literature review, targeted interviews with 22 government, industry and academic experts, and two focus groups. The report argues for stronger coordination, sustained funding and engagement with a wider range of suppliers, including smaller companies.
The authors propose an innovation centre to connect organisations and scale effective approaches. This is an institute policy research report, not an announced government programme or an experimental demonstration of better security outcomes. Its purposive expert sample can reveal barriers and mechanisms, but cannot establish what percentage of all suppliers encounter each problem. The focus-group count is not an additional count of independent organisations.[1]
Our analysis: a pilot needs an operational owner
The practical distinction is between proving that a tool can perform a task and establishing who will run it. Consider a system that helps an analyst sort a large set of public documents. A short demonstration may show useful retrieval. Routine use also requires a team responsible for source quality, access, error reports, software changes and continued funding. If those responsibilities remain unresolved, the demonstration can succeed while adoption stalls. This example illustrates an implementation question, not a finding about a specific classified project.
A buyer should be able to describe the operational problem without starting from a favourite model. Is the bottleneck the time spent locating records, checking translations or assessing conflicting accounts? Different problems require different tests and may not require a large generative model. A clear specification helps a smaller supplier show relevant capability without pretending to reproduce every feature of a frontier platform. It also gives procurement staff a basis for comparing proposals.
Faster adoption needs measurable safeguards
Our interpretation is that speed should be measured across the whole route into service. Reducing a purchasing delay is useful only if the system can subsequently be supported and checked. A time-limited pilot could publish non-sensitive measures such as review effort, false leads, reproducibility and the cost of switching suppliers. It should define what failure would stop expansion. The number of demonstrations held or partnerships announced would be a weak substitute for those operational measures.
People affected by security decisions have a stake even when they never use the software. An incorrect association in an analytical tool could consume investigators' time or draw attention to the wrong person. That possibility makes documented uncertainty and human accountability essential design questions. This article does not establish that any named system has caused such an outcome. It asks what evidence a public buyer should require before a pilot influences consequential decisions.
What would change the assessment
The proposed coordination approach would be more persuasive if subsequent projects disclosed milestones, costs and independently reviewed results where security permits. A new centre might remove duplicated work, but it could also add another layer of approval. Comparing the time and resources needed to move similar projects into supported service would help distinguish those possibilities. Suppliers should also have a clear account of why a project stopped, so public spending produces usable learning even when a technology is rejected.
The report concerns the UK, and its institutional recommendations should not be transplanted wholesale into another country's security system. Nevertheless, the questions about ownership, evaluation and long-term support are relevant to public AI procurement elsewhere. Our assessment would change if repeated operational trials showed both dependable benefits and manageable oversight costs. Until then, the report provides qualitative evidence about the conditions for collaboration, while the impact of the proposed reforms remains to be demonstrated.
What this means for people
- Accountable procurement matters for staff and for people affected by security decisions.
Global context
Institution-specific UK proposals require adaptation before use elsewhere.
What the evidence does not yet show
- Targeted qualitative sampling is not representative of every supplier or agency.
- Recommendations have not been tested as a causal intervention in this report.
What to watch next
- Operational evaluations and transparent costs of taking pilots into sustained service.
Evidence trail
Sources used for this report
Links checked 30 September 2026
This report is labelled source analysis. We summarise and analyse source material in our own words; company statements remain attributed claims until independently supported. Translated summaries preserve the meaning of the original source and link back to it. Read our editorial standards.
Continue the story
Related reporting
Security & Defence
What must UK AI researchers do after MI5's CGTRI espionage alert?
MI5 says more than 100 UK-linked academics contributed to research ultimately funded through a Chinese institute tied to China's civilian intelligence service. The alert requires immediate due diligence, but does not publish the underlying cases or evidence.
5 min · 4 sources
Security & Defence
Shared files carried a simulated attack between AI assistants; real-world spread is unproven
New analysis of a 28 September preprint: malicious instructions survived file hand-offs and persistent memory in synthetic workflows. The strongest results depended on an attacker-controlled external service, and no live outbreak was observed.
5 min · 2 sources
Security & Defence
UK AI Security Institute maps how frontier capabilities are changing
The AI Security Institute's Frontier AI Trends Report consolidates evaluations of model capability and safeguards to show where performance is improving and where risk evidence remains incomplete.
4 min · 1 source
Reader discussion
Add evidence, experience or a question
No account is required. Reader notes are published after a brief civility, relevance and safety check; disagreement is welcome.
Published reader notes
0No published reader notes yet. You can start the evidence-led discussion above.
Prefer a private correction or response? Contact the newsroom.