The direction from the NCSC is clear
On 22 June 2026, the UK National Cyber Security Centre published a joint statement from the leaders of the Five Eyes cyber security agencies. They described AI as a present change to cyber risk, not a distant one, and called on organisational leaders to act.
The statement says organisations should use AI deliberately to strengthen defence. It identifies earlier vulnerability detection and improved software quality among the benefits of integrating AI into security operations. At the same time, it stresses secure-by-design practice, leadership accountability, good security fundamentals and defence in depth.
The useful message is not “AI will solve security.” It is that defenders should learn how to use it responsibly while keeping every other important layer of defence in place.
Finding more is not the same as becoming safer
Separate NCSC guidance published on 11 May 2026 asks ten practical questions for organisations using AI models to find vulnerabilities. Several of them matter directly to software teams.
- Know what you are trying to achieve before selecting a model or tool.
- Have a process to receive, prioritise and fix the vulnerabilities AI reports.
- Understand information leakage, permissions, provider terms and data retention.
- Verify results using both AI and people.
- Continue investing in people who understand security.
That is a more demanding standard than running a model over a repository and counting how many issues it returns. A useful system has to manage context, evidence, prioritisation, human decisions and follow-up work.
Where Dokima fits
Dokima is one practical way for an engineering team to apply AI to defensive source review. It gives supported AI runners a bounded sequence of jobs: understand the codebase, plan focused review, hunt for issues, challenge the candidates, validate the evidence and explain the findings.
Dokima keeps the review state in the customer’s workspace and makes the output available as a developer-readable report. It is designed to help a team use AI as a repeatable security capability, not as a one-off prompt.
It remains one layer. Secure development practice, patching, access control, human judgment, independent assessment and the rest of a sound security programme still matter. That is consistent with the NCSC’s emphasis on defence in depth.
The NCSC and other Five Eyes agencies do not recommend, approve or certify Dokima. This article connects their published guidance with Dokima’s source-review workflow and links to the original material so readers can assess it directly.
Primary sources
- The AI shift in cyber risk: why leaders must act nowNCSC / Five Eyes statement · 22 June 2026
- 10 questions to ask when using AI models to find vulnerabilitiesNCSC · 11 May 2026
- Supporting AI adoption for UK cyber defenceNCSC · 23 April 2026