Tackling AI Uncertainty in Defence
Artificial intelligence is rapidly weaving itself into the fabric of UK defence. While the Ministry of Defence (MOD) accelerates AI adoption, the National Cyber Security Centre (NCSC) warns that this technology is fundamentally altering the cyber-threat landscape and the defensive measures required to meet it.
Yet, a critical vulnerability is often overlooked: what happens when employees do not feel comfortable disclosing how they use AI?
At Meritus, we regularly hold internal training, seminars, and honest thought tanks on the utilisation of AI in our practices, how we can use it to enable positive conversations and screenings with highly technical, highly knowledgeable professionals. However, whilst this might initially seem like an internal HR or culture challenge, within the defence sector, it represents a profound cyber-security risk which this week’s AI-news melt-down might have well exposed.
This article includes insight from Jake Appleton, Managing Director at Meritus, who works closely with leading defence employers across the UK.
The Cost of Transparency
Recent research from KPMG highlights a stark disconnect: 58% of surveyed employees use AI at work, but just 57% admit to doing so opaquely, and nearly half operate outside official organisational policies.
The core issue here is not that personnel are experimenting with AI; it is that adoption is outpacing governance and its inherent self-development is difficult to control. Employees are increasingly uncertain as to which tools are authorised, what data can be safely processed or whether using AI will lead to professional repercussions, so they are choosing to remain silent.
This can trigger a chain reaction:
- Ambiguity: A lack of clear guidelines on approved tools and data boundaries.
- Secrecy: Employees then bypass policy to maintain productivity.
- Blind Spots: Organisational visibility into unsanctioned shadow IT diminishes.
- Vulnerability: Undocumented AI usage drastically expands the cyber attack surface.
In standard commercial sectors, unauthorised AI use might inadvertently expose intellectual property or proprietary data. Within the UK defence ecosystem, comprising of major primes, agile SMEs, contractors, and specialist supply chains, the stakes are exponentially higher.
Cyber resilience in defence relies on a collective security posture and a zero-trust environment. A contractor utilising an unapproved third-party AI tool to draft a technical document or analyse operational data likely has no malicious intent; they are simply trying to save time.
However, they may not comprehend the data exposure risks, or they may conceal their actions out of fear of disciplinary action. While technical controls, prompt injection safeguards, and robust firewalls remain vital, no software architecture can compensate for a workforce too afraid to raise their hand.
Why Blanket Bans Don't Work

Faced with sensitive classified or official-sensitive information, some organisations default to blanket prohibitions. However, outright bans rarely eliminate usage. If employees already rely on AI workflows, a prohibition merely drives their habits underground, deepening the visibility gap.
A resilient, sustainable approach replaces prohibition with structured controls and psychological safety. Personnel must receive unambiguous guidance on:
- Exactly which platforms are approved for use.
- What specific data can and cannot be inputted.
- When AI-generated outputs demand mandatory human oversight and verification.
- Who holds ultimate ownership of the final product.
- Immediate steps to take if sensitive data is accidentally shared.
- Designated points of contact for guidance without fear of judgment.
In discovery of these issues, when uncertainty arises, staff must feel safe to ask for help.
Cyber Security as a Cultural Imperative
The MOD's work on responsible AI rightly emphasises governance, accountability, and safe adoption. For defence contractors and institutions, this mindset must extend far beyond technical parameters into daily workplace culture.
Leadership must actively create an environment where disclosing a mistake or raising a compliance concern is met with constructive guidance rather than retribution. If an employee reports, "I am unsure if I was allowed to use AI for this task," leadership gains immediate visibility and an opportunity to mitigate risk. If that same employee stays silent, the organisation is left blind.
As AI embeds itself deeper into defence operations and multi-tier supply chains, visibility remains the bedrock of cyber defence. An organisation cannot protect what it cannot see.
Ultimately, the defining question for the UK defence industry is: Can we build workplaces where our people feel trusted enough to be honest about how they use it?
How we can help:
Building secure AI-enabled organisations requires the right culture, clear governance, and people who understand both innovation and risk. At Meritus, we support defence organisations in securing the specialist talent needed to navigate emerging challenges across cyber security, AI, engineering and technology. If you're planning for the future of AI adoption, we'd be happy to start the conversation.
If you're planning for the future of AI adoption, get in touch.















