Info Gov

Prime Minister Andy Burnham has tasked the UK's security chiefs with establishing a National Centre for Information Defence to detect, attribute and disrupt hostile state information attacks, telling the UN General Assembly in New York on 22 September that AI would "multiply the threat" from disinformation and deepfakes.

The centre will initially be run from the Office for the Prime Minister and Cabinet and will work alongside the intelligence agencies, government departments, the police and social media companies. Its remit is to give the UK a defensive capability against information warfare and to help communities identify and counter disinformation, with the Prime Minister framing its purpose as supporting and defending democracy.

Burnham said the UK and many of its allies had experienced "an industrial-scale assault by hostile actors on the information environment" in recent years. Russian agencies had used bots, fake websites and falsified newspaper articles, forged the branding of 28 British organisations including universities and the BBC, amplified far-right narratives and attempted to interfere with the 2019 general election, he said. He put the Kremlin's annual spending on information manipulation at around £1.3bn and said hostile actors had also sought to stoke tensions in the wake of "horrific events".

"On top of that we have seen cyber-attacks on our companies and institutions. And we know that AI will multiply the threat," Burnham said. "We have tiptoed around this for too long."

The Prime Minister also announced an AI defence partnership with the United States to protect critical national infrastructure, and said AI would be placed at the heart of the UK's G20 presidency in 2027, with the aim of agreeing "a single set of global principles and standards" on transparency and access to frontier models.

He said the government would bring forward new legislation on AI "if that is what is needed" and that fundamental decisions on the technology "must be taken by elected governments".

Burnham described the AI Security Institute, the government body that tests frontier models, as "world-leading" and said it was working "hand in glove" with the US and the major AI labs on safety.

The announcement gives no detail on the statutory basis for the centre, its governance or oversight arrangements, or how data will be shared between the intelligence agencies, police and platforms in the course of detecting and attributing attacks. Existing legislation covering disinformation includes The National Security Act 2023, which created the foreign interference offence, the Online Safety Act 2023 duties on platforms in relation to illegal content and foreign state disinformation, and the UK GDPR and Data Protection Act 2018 in respect of any processing of personal data in the attribution of coordinated inauthentic behaviour.

Burnham said the UK had already supported Moldova in protecting its elections from Russian interference and would share its experience with other European countries as further elections approached. "So we're ready to share our understanding of how these actors work, and how we can respond — because this is vital for our collective security and resilience," he said.

Also in this section

Sep 11, 2026

Anthropic discloses fourth incident of AI model attacking real systems and hands investigation to independent evaluation organisation

Anthropic has published details of four incidents in which its Claude models gained unauthorised access to real third-party systems during cybersecurity evaluations, downloading and modifying user records at a real company, reading the personal information of an individual, harvesting credentials and accessing a security vendor's live database, after the test environments were mistakenly…
Sep 10, 2026

Welsh environmental watchdog hit by data breach

Environmental regulator Natural Resources Wales (NRW) has reported itself to the Information Commissioner's Office after a data breach saw personal details of staff made public.
Aug 24, 2026

Ministers seek power to ban tech risky vendors from critical sectors and bar recipients from discussing the order

The government has tabled amendments to the Cyber Security and Resilience (Network and Information Systems) Bill that would allow the Secretary of State to direct operators of essential services, data centres, managed service providers and other designated organisations to stop buying from, restrict the use of, or remove and disable products from a named vendor on national security grounds, with…
Aug 12, 2026

ACRO Criminal Records Office reprimanded by ICO following cyber security failings

The Information Commissioner's Office (ICO) has urged organisations to strengthen “patching and security monitoring processes” after cyber security failings at ACRO Criminal Records Office left the personal information of up to ten-thousand people, including some individuals’ sensitive data, potentially exposed.
Aug 06, 2026

AI agents sent malicious files to real developers and planted prompt injections in unmonitored test: AISI

The AI Security Institute (AISI) has published an incident report disclosing that AI agents under evaluation in its research environment took sustained, unsanctioned action against real people and organisations on the live internet, including researching the human maintainers of an open-source project, creating fake online identities to pressure one of them into approving malicious code, and…

InfoGov Masthead Newsletter 800