Centre for Long-Term Resilience – Written evidence (NLR0095)
About CLTR
The Centre for Long-Term Resilience is an independent think tank working to transform global resilience to extreme risks. CLTR works closely with policymakers across Whitehall on national resilience architecture, contributing to the development of the Government's approach to catastrophic risk management, resilience exercising, and the governance of emerging technologies including artificial intelligence. CLTR's Risk Management Policy unit specialises in the application of established risk management frameworks to novel and cross-cutting threats.
Executive Summary
The fundamental problem which has dogged the UK Government's resilience planning for extreme risks - such as those from emerging technology - has been its inability to match the complexity of these risks with the cross-cutting institutional coordination, long-term resource planning and specific expertise required to anticipate and mitigate them. Effective preparedness and response has been undermined by departmental silos, a lack of specialist expertise across government and the absence of required resourcing. The Covid-19 experience led to some incremental structural improvements, so far largely untested.
The rapid advances in AI across all measured domains in the years since require a step change in the Government's resilience capability and its governance of emerging technology.[1] Performance in key areas is now doubling every 4 months and AI systems are surpassing the performance of human experts in an increasingly wide range of tasks. The OECD ‘Exploring possible AI trajectories through 2030’ working paper[2] and the ‘International AI Safety Report’[3] both find that AI systems capable of broadly exceeding human cognitive capabilities are plausible by 2030, a scenario for which the UK is critically unprepared.
While some risks stem from how the UK itself adopts AI, many of the most severe will stem from broader changes to the global risk landscape: from the collapse of barriers to catastrophic misuse, to loss of control over advanced autonomous systems, to the degradation of the information environment. New models, including Claude Mythos, present an unprecedented cybersecurity threat. Anthropic's latest model, Claude Mythos, can discover and exploit[4] previously unknown software vulnerabilities and was found to be able to identify and exploit zero-day vulnerabilities in every major operating system and every major web browser. 99% of these vulnerabilities remain unpatched. Threat actors are already using other autonomous AI agents to conduct fully automated cyber attacks.[5] Adversaries including Russia are stepping up AI-enabled attacks on Critical National Infrastructure and sharing surveillance technologies offensively.[6]
The UK must be prepared for these changes to the global AI landscape regardless of its own pace of adoption. Yet whilst the government's own AI Opportunities Action Plan[7] - published in the same month as the 2025 National Risk Register[8] - concluded that AI may be the most important technology of our time, the NRR mentions AI only three times in 187 pages.
The opportunity in 2026 is to build on the progress made separately on resilience and on AI security in the past five years. This can be done by instituting cross-cutting AI governance mechanisms, inspired by the best practice 'three lines' model codified in HM Treasury's Orange Book[9], into existing Whitehall architectures. It is no longer enough to silo AI expertise within dedicated departments or bodies: a whole-of-government approach with distributed risk governance will be needed to adequately strengthen the UK's capacity to manage a rapidly evolving threat landscape driven by geopolitical as well as technological change.
This evidence is submitted in response to the Committee's questions on the interconnectedness of risks across sectors and timeframes, barriers to implementing improvements to preparedness and resilience (including inappropriate structures), and whether the current structures within government are adequate for managing resilience and ensuring cross-departmental coordination.
1. Why AI demands new governance architecture
The UK has restructured before - and must do so again
- The UK has historically met transformative threats by building dedicated institutional architecture. Nuclear technology was not left to existing departments; the government created the UK Atomic Energy Authority in 1954 to separate research from regulation. Biosecurity followed a similar path with the UK Health Security Agency. In each case, the government recognised that a cross-cutting, technically complex challenge could not be governed by vertical departmental structures alone.
- AI is at least as cross-cutting as biosecurity and moving faster than nuclear technology ever did. It demands an equivalent leap in institutional innovation.
Four structural reasons why the current model is insufficient
- Jurisdictional fragmentation: The current Lead Government Department (LGD) model assumes risks stay within specific areas. AI, however, is a horizontal technology still being managed by vertical institutions. No single department has the remit, resources, or cross-government visibility to coordinate a coherent response, creating an ownership vacuum. The COVID-19 Inquiry's Module 1 report found that the UK's preparedness was hindered by a fragmented institutional landscape when a unified response was required.[10] AI presents an even more complex version of this problem: it is not just an external risk to be mitigated, but a transformative capability being adopted by every department concurrently, while simultaneously reshaping the global threat landscape in ways that no single department can monitor alone. The Cabinet Office has established central coordination for catastrophic risks, including jointly chaired preparedness committees with relevant Lead Government Departments. However, because AI is not yet called out in the NSRA as an independent risk, no such committee currently owns it, leaving threats such as catastrophic loss of control or loss and malfunction of critical AI systems without a clear owner.
- Categorical novelty: The current approach treats AI primarily as an accelerant of existing risks, such as "AI-enabled cyber attacks”. This is a category error. AI introduces fundamentally novel risk surfaces that the current National Risk Register is not designed to capture. These include: loss of control, where advanced systems operate outside human oversight; the elimination of expertise barriers that previously gated access to catastrophic capabilities, meaning that biological or radiological harm once confined to state-level actors may become accessible at a pace that outstrips traditional counter-proliferation; loss or malfunction of critical AI systems increasingly fundamental to financial services, energy and defence; and slow-burn systemic disruption, including the gradual degradation of public discourse and institutional decision-making. Many of these risks are not contingent on the UK's own adoption choices - they will materialise as a consequence of global AI development regardless of domestic policy. Simply adding these categories to the NRR is necessary but insufficient. Novelty creates a critical vulnerability: the latency between detection and understanding. The government requires a risk-agnostic management system that can scale to address anomalies the moment they are detected.
- Expertise deficit: The Civil Service generalist model, in which officials rotate through departments every two to three years, cannot sustain the technical depth AI requires. Evaluating whether an AI system in NHS diagnostic imaging is safe requires deep understanding of both AI and clinical triage. Where the government has bypassed the generalist model, e.g. through the Vaccine Taskforce or the AI Security Institute - the results have been world-leading. However, these remain exceptions. Without sustained specialist expertise embedded within departments, and a mechanism to link that expertise across Whitehall, the government will continue to make decisions in isolation. This challenge extends to the UK Intelligence Community, where the ability to recruit and retain frontier AI talent is an active and urgent concern.
- Temporal mismatch: The gap between AI's pace of development and the speed of government institutional learning is widening. Traditional governance operates on cycles measured in years; AI deployment moves on a trajectory that outstrips standard windows for spending reviews, legislative sessions, and risk assessments. This is most acute in resilience exercising. To date, the UK has not conducted a Tier 1 exercise centred on an acute AI incident. Even when exercises are conducted, the feedback loop is too slow: the report from Exercise Pegasus (the Autumn 2025 pandemic exercise) is not expected until Winter 2026, some 15 months after the exercise itself. For AI, the risk vectors an exercise was designed to address will likely have been superseded within that timeframe.
2. The scale of the structural mismatch
- The government's own outputs illustrate the disconnect. The AI Opportunities Action Plan is being implemented as a priority, with 38 of 50 actions completed within twelve months and £14 billion in private investment secured.[11] On safety and resilience, however, progress is more hesitant: the 2025 National Risk Register mentions AI only three times in 187 pages, with no dedicated entry for acute AI risks. The current machinery treats AI strategy and AI risk as separate concerns, managed by different teams on different timelines, when the reality is that AI is reshaping the global risk landscape faster than either track can respond to alone.
A 'three lines' model for AI governance
- We propose a version of the 'three lines' model for AI risk governance operating across government. The three lines model is already the mandated standard for risk management across the UK Government, as codified in HM Treasury's Orange Book. The Government is already moving in this direction for resilience: the Resilience Action Plan (July 2025) introduces a three-tier assurance model; self-assurance, assurance by system leaders, and independent external review, which maps closely to the three lines logic.[12] The structural template for governing AI is not foreign to Whitehall; it is emerging within it.
- However, the unique characteristics of AI, its cross-cutting nature, technical opacity, and potential for irreversible harm, demand that we move beyond the standard application of this model. In its standard Orange Book application, the third line is fulfilled by internal audit. For AI, we argue this external layer must be brought inside the architecture as a permanent, structural feature: independent scrutiny that sits outside government and reports to Parliament.

First Line: Departmental ownership
- AI Adoption Leads should be appointed in every government department, with the technical depth and seniority to make informed decisions about AI strategy, deployment and risk at pace. These officials own AI risk in their specific domains, embedding specialist expertise within each department and translating AI opportunities and risks into sector-specific recommendations. They should be new, dedicated technical hires. We suggest consideration of a dedicated AI fast stream to build this capacity systematically.
- An AI Security Coordination Unit, sitting within the Cabinet Office, should coordinate AI risk ownership across the first line and the work of the departmental AI Adoption Leads. This mirrors the Biological Security Coordination Unit and provides the horizontal anchor the current architecture lacks. AI risk would be collated by this Unit and reported into the COBR Directorate's NSRA/NRR section, slotting into the existing resilience architecture.
- A National Security Council sub-committee for AI (NSC-AI) should be established, chaired from the centre of government, to ensure that frontier AI risks - including those driven by global developments beyond the UK's direct control - are integrated directly into strategic security decision-making.
Second Line: Specialist oversight and surge capacity
- An AI Security Adoption Accelerator should be created as a standing unit of deep technical talent. This should include engineers, AI policy experts, and “red teamers”, deployable across departments to support high-stakes projects, share cross-government intelligence, and provide emergency triage for AI incidents. This is distinct from the No.10 Innovation Fellowship,[13] which brings external talent into government for time-limited project secondments. The Accelerator would comprise permanent specialists already versed in departmental operations and the machinery of government, capable of both planned deployment and rapid crisis response - including serving as first responders to novel AI risk events for which no departmental playbook yet exists. Its operating model draws on two proven precedents: the Vaccine Taskforce's ability to inject private-sector pace into a cross-cutting crisis, and GCHQ's model of embedding specialist advisors within departments that lack in-house capability. Ownership of risk remains with the First Line; the Accelerator advises and supports.
- A Chief Advisor for AI should provide cross-cutting expert guidance on AI strategy, working directly with the Prime Minister and DSIT Secretary of State on AI policy and implementation. This recommendation formalises and embeds the existing advisory function, ensuring continuity beyond any single appointment.
Third Line: Independent assurance and democratic scrutiny
- An independent Office for AI Responsibility, constituted as a Non-Departmental Public Body under the Cabinet Office and modelled on the Office for Budget Responsibility, should perform external audits of AI risk management across government, with a focus on the most severe risks to the nation. It should also scrutinise AI risk preparedness and related processes. Its red-teaming function would stress-test the governance architecture itself: auditing whether departmental risk assessments are adequate, testing incident escalation pathways through simulated scenarios, and evaluating whether first and second line management of novel risks is sufficient. This is governance assurance, not model or system assurance, and is distinct from the AI Security Institute's existing mandate of frontier model evaluation and research. AISI's world-leading work on frontier model evaluation and its productive engagement with the national security community should be preserved and supported; the Office for AI Responsibility addresses a different gap - ensuring that the governance layer above and around those technical functions is itself fit for purpose.
- A Joint Parliamentary Committee for AI, drawn from both Houses, should provide democratic scrutiny of the government's AI strategy and the Office for AI Responsibility's assessments, ensuring transparency and accountability.
Democratic legitimacy
- Underpinning the three lines is a Citizens' AI Council: a permanent deliberative body ensuring that the ethical and social trade-offs inherent in government AI strategy remain aligned with public values. AI poses questions that no amount of expert oversight can resolve: when a technology has the potential to reshape labour markets, alter democratic participation, and change the relationship between citizen and state, the choices the government makes about it are political choices. And political choices, in a democracy, belong to the public. A standing Council provides the mechanism for that deliberation - not as a veto, but as a structured, informed process through which citizens can set the boundaries within which the three lines operate. Without it, the government risks building a governance architecture that is technically robust but democratically hollow.
Resilience leadership
- Beyond the AI-specific architecture proposed above, these structural challenges point to a broader gap in resilience leadership. The 2021 Lords report recommended a Government Chief Risk Officer.[14] The Covid-19 Inquiry went further in calling for independent scrutiny of resilience preparedness.4 Neither recommendation has been fully implemented. We propose the appointment of a Chief Resilience Officer operating as an additional Deputy National Security Adviser, with the COBR Directorate reporting to them. This role would provide the senior, sustained leadership needed to drive risk management discipline across Whitehall, not only for AI, but for the full spectrum of catastrophic and emerging risks. Without a named individual at this level owning the resilience agenda, the structural improvements of recent years risk remaining a set of mechanisms without a driver.
Risk culture
- The three lines model both depends on and facilitates healthy risk culture. By clearly separating "doing" from "checking", it makes raising concerns a sign of professional competence rather than an admission of failure. A robust assurance structure provides the institutional confidence required for departments to engage with AI at an ambitious pace. Without that assurance, the rational strategy is caution. For a technology that is reshaping the global landscape faster than Whitehall's standard learning cycle, this cultural shift from blame to assurance is both a precondition for the architecture and a secondary benefit of it.
3. Recommendations
This submission calls on the Government to adopt the following measures as part of a unified AI governance framework:
First Line
- Appoint an AI Adoption Lead in every government department, with technical depth and seniority to own AI strategy, opportunity and risk. Consider establishing a dedicated AI fast stream.
- Establish an AI Security Coordination Unit within the Cabinet Office, modelled on the Biological Security Coordination Unit, reporting AI risks into the COBR Directorate's NSRA/NRR section.
- Create a National Security Council sub-committee for AI (NSC-AI), chaired from the centre of government.
- Appoint a Government Chief Resilience Officer operating as an additional Deputy National Security Adviser, with the COBR Directorate reporting to them.
Second Line
- Create an AI Security Adoption Accelerator as a standing, deployable unit of specialist talent for departmental support, cross-government intelligence sharing, and emergency triage.
Third Line
- Establish an independent Office for AI Responsibility as a Non-Departmental Public Body, with a statutory mandate to audit AI governance across government and publish findings independently.
- Establish a Joint Parliamentary Committee for AI to provide scrutiny of the Government's AI strategy.
Democratic engagement
- Create a permanent Citizens' AI Council to deliberate on the ethical and social boundaries of government AI strategy and involve the wider public in these issues.
Risk assessment and exercising
- Add dedicated entries for acute AI risks to the National Security Risk Assessment and National Risk Register, recognising AI as a source of categorically novel as well as an accelerant of existing threats - both of which are driven by global developments beyond the UK's direct control.
- Conduct a Tier 1 national exercise centred on an acute AI incident, with published findings within three months and named ownership of all recommendations.
- Conclusion
- These recommendations are largely co-dependent. Each element in the framework proposed depends to some extent on the others; adopting them selectively could accentuate the fragmentation this submission has highlighted.
- AI will be the defining governance challenge of this generation. The question is not whether the UK Government will need architecture of this kind, but whether it builds it proactively, as a considered act of institutional design, or reactively, under crisis conditions. Under those circumstances the cost of improvisation would be significant, and worsened by eroded public trust and exploited governance gaps.
- A final note on devolution: AI adoption in health, education, and policing is substantially devolved. The AI Security Coordination Unit should include a formal interface with the Devolved Administrations, mirroring existing resilience coordination arrangements, and this should be formalised in the Unit's terms of reference.
20 April 2026
[1] AISI, Frontier AI Trends Report (18 December 2025)
[2] OECD, Exploring possible AI trajectories through 2030 (3 February 2026)
[3] International AI Safety Report 2026 (3 February 2026)
[4] Anthropic, Project Glasswing
[5] Anthropic, Detecting and countering misuse of AI (27 August 2025)
[6] Foundation for Defense of Democracies, Russia’s AI-Powered Cyberattacks Threaten to Outpace Western Defenses (20 February 2025)
[7] Department for Science, Innovation and Technology, AI Opportunities Action Plan, CP 1241 (13 January 2025).
[8] Cabinet Office, National Risk Register 2025 (16 January 2025).
[9] HM Treasury, The Orange Book: Management of Risk - Principles and Concepts, Annex 2: The Three Lines Model (May 2023)
[10] UK Covid-19 Inquiry, Module 1 Report: The Resilience and Preparedness of the United Kingdom (2024).
[11] Department for Science, Innovation and Technology, AI Opportunities Action Plan: One Year On (29 January 2026).
[12] Cabinet Office, UK Government Resilience Action Plan (14 July 2025).
[13] The No.10 Innovation Fellowship Programme.
[14] House of Lords Risk Assessment and Risk Planning Committee, Preparing for Extreme Risks: Building a Resilient Society (2021).