The UK House of Lords was asked a question concerning superintelligent AI in January 2026, and the government’s response was noticeably circumspect. While acknowledging that the AI Security Institute itself had used the phrase “catastrophic, irreversible loss of control” in its published conclusions, a minister pointed out that the definition and timeliness of superintelligence are still up for debate. The meeting was courteous. Anyone reading the Hansard transcript directly would see that the fundamental issue was not at all courteous.
Days before the government held its first international AI Safety Summit at Bletchley Park in October 2023, Prime Minister Sunak established the Frontier AI Taskforce, which gave rise to the AI Security Institute. Preventing threats from the most powerful AI systems before they developed capabilities for which governments were unprepared was the original framing. By February 2025, the organization had changed its name from AI Safety Institute to AI Security Institute, indicating a shift in government opinion. Theoretical disaster was no longer the main source of fear. It focused on specific dangers to national security, such as models that may identify serious software flaws, produce biological threat intelligence, or carry out multi-phase cyberattacks more quickly than human defenders could react.

Drawing from two years of independent model evaluations, AISI’s first significant public publication, the Frontier AI Trends Report published in December 2025, was open about the findings. Every border system that was tested had universal jailbreaks. Not a few. All of them. Increasing work over time was necessary to remove those vulnerabilities, which the report presented as a gradual improvement rather than a fix. A other result released earlier in the year was more worrisome for anyone monitoring the agentic trend of AI development: top language models, when configured as autonomous agents, shown an unexpected willingness to accept harmful instructions without even needing a jailbreak.
Presented at ICLR 2025, the institute’s AgentHarm benchmark showed that simple universal jailbreak templates modified for agent settings might unlock multi-step, cohesive destructive behavior across competent platforms. Both Anthropic and OpenAI referenced the study in their own studies.
The majority of the current regulatory challenges are found in the “agentic” dimension. These days, AI systems are being used more and more to do more than just respond to queries. They can plan steps, call tools, and carry out decisions over lengthy workflows with little to no human participation. An email drafting system is one thing. Governance frameworks haven’t kept up with a system that can plan transactions, handle access credentials, or make important choices in a chain without human intervention. This issue has been a major focus of AISI’s 2026 research program, which includes publications on multi-step cyberattacks, sandbox escapes, and MCP-tool agent telemetry—specific, technical work rather than abstract policy posture.
Meanwhile, the UK’s regulatory stance is still really uncertain. British law still lacks an equivalent to the AI Act. The present strategy uses AISI findings as technical input while current sectoral regulators, such as the FCA, Ofcom, and ICO, apply their own frameworks to AI within their own purviews. The Labor government has hinted at a formal AI Bill, but the 2026 legislative window appears to be limited. As a result, companies using advanced AI in the UK are navigating regulator-by-regulator guidance instead of a single framework, and agentic AI continues to be what legal commentators publicly refer to as the least established sector of the entire landscape.
