Public sector leaders can secure artificial intelligence (AI) only by treating security as a fast-moving target, by demanding secure-by-default and interoperable technology, and by leaning on open source to build trust and resilience. They can also use their collective purchasing power to shape the market rather than simply buy from it.
That was the message from two public sector voices on a security panel at this week’s AWS Public Sector AI Symposium in London: Caroline Gorski (pictured, right), director of the Digital Commercial Centre of Excellence (DCCOE), and Laura Gilbert (pictured, left), senior director of AI at the Tony Blair Institute.
The panel focused on a question government leaders keep asking: “How do I deploy AI securely?” The security backdrop came from Jason Gwartz, head of core technology at the AI Security Institute (AISI), a Cabinet Office directorate.
The AISI tests frontier models against simulated corporate networks and pieces of critical national infrastructure that a model must attack end-to-end. Last year, models solved only a handful of steps on ranges it designed with 30 or more. In April, a model completed all 32 steps of one range autonomously for the first time. Gwartz put the doubling time of cyber skills at around five months.
Against that context, Gilbert and Gorski offer two different answers to the security question – one technical, one commercial.
Gilbert, who ran the data science and AI team in Downing Street for four and a half years before joining the Tony Blair Institute, which advises just under 50 governments on using AI for public services, opens not with security, but inequality. Done well, she argued, AI narrows the gap; done badly, it widens it and breeds unrest.
She described the UK as “the third most unequal country in the OECD developed nations”, a position that “costs us somewhere between £35bn and about £70bn a year”. The upside is concrete: “Reducing inequality to the mid-level is predicted to reduce people being imprisoned by about 30%, mental health problems by about 5% and murders by 33%.”
Open source for security
Gilbert’s answer to the IT security question is transparency, in the form of open source. In Downing Street, she “immediately adopted this mantra of radical transparency”, open-sourcing all of the team’s code, and publishing blogs on what they built and why.
For government, argued Gilbert, open source does two things. It cuts cost: “I don’t think that we should be competing with big frontier apps on absolute top-tier technology,” she said. “We need models that are very cheap and that can be run on completely constrained infrastructure for security reasons, that are good enough.”
And, counter-intuitively, it improves security: publishing code invites scrutiny rather than inviting attack. “We never once had anyone manage to hack into anything, but we would give them a prize if they did,” said Gilbert. “If you don’t open source, very often, what you’re doing is leaving a space for the bad actors to come in who might be better funded and more determined. And they will find the hole.”
She made the point about how framing shapes acceptance, with the example of an “AI pharmacist”. Tell people “we’re building an AI pharmacist” and they recoil, said Gilbert, but point out that “in the UK, we kill about 22,000 people every year with bad prescriptions, and it costs about a billion pounds, and we don’t have the manpower to solve that”, and it “sounds like a little bit of a better idea”.
Public sector as leader
Where Gilbert reaches for code, Gorski reaches for contracts. The DCCOE blends commercial, technical and delivery expertise and exists, she said, “to help the government and the public sector to become a more ambitious and more intelligent customer for transformative digital technologies”.
The insight behind her argument is that the public sector is a buyer big enough to set terms. As “probably one of the largest single customers” for many AI services, it should “use more of that power and weight to actually shape the markets, not simply to buy what’s already available”. The cloud challenge book, launched earlier this year, sets out those challenges.
“One of the things that we haven’t necessarily done well across government is understand our purchasing power collectively, and what that frees us to ask for from our suppliers in a much more directive and pointed way,” she said.
In practice, Gorski wants price discounts and opportunities to innovate to reach everywhere, “not just in central government, but also in the devolved authorities and the local government”. She wants “interoperability, portability, removing exit penalties” to be “baked into the way that we engage with our technology partners” – including “failover protocols that might fail over to competitors’ service provision” if a cloud region goes down.
The underlying challenge, said Gorski, is for suppliers to deliver “the underlying capabilities to be secure by default, to be resilient by default, to be transparent by design, and to have public value as their primary objective”.
The two arguments converge in the same place. Gilbert said the decisions made now – “who you allow to have access to your data” – will “fully impact the society that we go forward into, our children go forward into”. Gorski framed it as a duty: “Government’s role in emerging markets is to shape emerging markets. And we have a social responsibility to shape those markets in line with what our society wants us to do.”

