By Jake Appleton
•
September 16, 2026
Artificial intelligence is rapidly weaving itself into the fabric of UK defence. While the Ministry of Defence (MOD) accelerates AI adoption , the National Cyber Security Centre (NCSC) warns that this technology is fundamentally altering the cyber-threat landscape and the defensive measures required to meet it. Yet, a critical vulnerability is often overlooked: what happens when employees do not feel comfortable disclosing how they use AI? At Meritus , we regularly hold internal training, seminars, and honest thought tanks on the utilisation of AI in our practices, how we can use it to enable positive conversations and screenings with highly technical, highly knowledgeable professionals. However, whilst this might initially seem like an internal HR or culture challenge, within the defence sector, it represents a profound cyber-security risk which this week’s AI-news melt-down might have well exposed. This article includes insight from Jake Appleton , Managing Director at Meritus, who works closely with leading defence employers across the UK. The Cost of Transparency Recent research from KPMG highlights a stark disconnect: 58% of surveyed employees use AI at work, but just 57% admit to doing so opaquely, and nearly half operate outside official organisational policies. The core issue here is not that personnel are experimenting with AI; it is that adoption is outpacing governance and its inherent self-development is difficult to control. Employees are increasingly uncertain as to which tools are authorised, what data can be safely processed or whether using AI will lead to professional repercussions, so they are choosing to remain silent. This can trigger a chain reaction: Ambiguity: A lack of clear guidelines on approved tools and data boundaries. Secrecy : Employees then bypass policy to maintain productivity. Blind Spots: Organisational visibility into unsanctioned shadow IT diminishes. Vulnerability: Undocumented AI usage drastically expands the cyber attack surface. In standard commercial sectors, unauthorised AI use might inadvertently expose intellectual property or proprietary data. Within the UK defence ecosystem, comprising of major primes, agile SMEs, contractors, and specialist supply chains, the stakes are exponentially higher. Cyber resilience in defence relies on a collective security posture and a zero-trust environment. A contractor utilising an unapproved third-party AI tool to draft a technical document or analyse operational data likely has no malicious intent; they are simply trying to save time. However, they may not comprehend the data exposure risks, or they may conceal their actions out of fear of disciplinary action. While technical controls, prompt injection safeguards, and robust firewalls remain vital, no software architecture can compensate for a workforce too afraid to raise their hand . Why Blanket Bans Don't Work