AI Systems Became an Inventory Problem: What the NCSC 2027 Assessment Means for Exposure Discovery
In May 2025 the UK National Cyber Security Centre published Impact of AI on cyber threat from now to 2027, its assessment of how AI developments change cyber intrusion between now and 2027. One judgement reframes the whole topic.
The growing incorporation of AI models and systems across the UK's technology base, and particularly within critical national infrastructure (CNI), almost certainly presents an increased attack surface for adversaries to exploit.
That is a statement about asset management. Every model runtime, notebook server, orchestration platform and vector store added to support AI work is another reachable service. The assessment names techniques that already turn those services against their owners: direct prompt injection, indirect prompt injection, software vulnerabilities and supply chain attack.
What the assessment claims
The report is explicit about scope. It covers AI in cyber intrusion and excludes wider AI-enabled threats such as influence operations. It uses the PHIA probability yardstick rather than absolute certainty. Its key judgements are worth quoting precisely:
- AI will almost certainly continue to make elements of cyber intrusion operations more effective and efficient, increasing the frequency and intensity of cyber threats.
- By 2027, AI-enabled tools will almost certainly enhance threat actors' capability to exploit known vulnerabilities, increasing the volume of attacks against systems that have not been updated with security fixes.
- Proliferation of AI-enabled cyber tools will highly likely expand access to intrusion capability across a wider range of state and non-state actors.
- Assuming a lag, or no change to cyber security mitigations, there is a realistic possibility of critical systems becoming more vulnerable to advanced threat actors by 2027. Nothing here depends on a novel vulnerability class. It depends on reachable systems whose owners do not know they are reachable.
Measure the surface, do not assume it
An attack-surface argument only becomes actionable when the surface can be seen. Cyberspace search engines offer one external view, built from product fingerprints rather than from internal inventory. The observations below were collected on 3 October 2026 through ZoomEye. Every query returned a successful status, and each figure is the total number of matches the engine reported.
| Fingerprint query | Matches observed | Role in the argument |
| --- | ---: | --- |
| app="Ollama" | 602,744 | Model runtime, any port |
| app="Ollama" && port="11434" | 126,482 | Same runtime on its default API port |
| app="Open WebUI" | 90,190 | Browser front end for local models |
| app="Jupyter Notebook" | 90,610 | Interactive compute with code execution |
| app="n8n" | 414,336 | Workflow automation wired to credentials |
A reproducible example is the search link below, which encodes the narrower query app="Ollama" && port="11434".
👉 https://www.zoomeye.ai/searchResult?q=YXBwPSJPbGxhbWEiICYmIHBvcnQ9IjExNDM0Ig%3D%3D
Read fingerprint counts correctly
A fingerprint match is not a vulnerability count. A host matching app="Ollama" is identified as advertising that software. The observation does not establish that it is unpatched, misconfigured, exploitable or interesting to any particular adversary. Identification can also be wrong or stale.
What the figures do support is a planning statement rather than an incident claim: model runtimes and the tooling around them are widely deployed on internet-facing infrastructure. An inventory built only from an internal asset database will miss software that was never registered, including pilot deployments, developer laptops behind a port forward and shadow AI services installed by a business unit.
Practical next steps
- Enumerate every AI-related service the organisation runs, including pilots, proofs of concept and unregistered deployments.
- Compare that list with an external exposure view to find services reachable from the internet.
- Record the exact query, collection time and scope of each observation so the figures can be reproduced later.
- Treat interfaces capable of prompt injection and unauthenticated control planes as high-priority findings.
- Re-measure on a schedule, because the assessment's own framing is that the technical picture changes fast and surprise is likely.
Limitations
This analysis combines a public scan of internet-facing services with one published national assessment. It contains no non-public telemetry and cannot attribute any observed exposure to any named organisation. The NCSC judgements describe likelihood ranges, not certainty, and the report warns that AI technical surprise is likely before 2027.
References
- NCSC, Impact of AI on cyber threat from now to 2027: https://www.ncsc.gov.uk/report/impact-ai-cyber-threat-now-2027
- NCSC, The near-term impact of AI on the cyber threat: https://www.ncsc.gov.uk/report/impact-of-ai-on-cyber-threat
- ZoomEye: https://www.zoomeye.ai/
Top comments (0)