
TL;DR: The UK finally realized AI might do more harm as a weapon than as an insensitive chatbot. They’ve rebranded their AI ‘Safety’ Institute to ‘Security’ Institute to focus on actual threats like fraud and cyberattacks. Took them long enough, but don’t applaud yet: geopolitics pushed this change more than common sense.
The great AI safety versus security debate has finally reached its inflection point. The UK’s decision to rebrand its AI Safety Institute as the AI Security Institute could mark a watershed moment in how governments approach artificial intelligence risks. While the shift itself is overdue, the path that led us here leaves much to be desired.
All about feelings
For the past few years, I’ve watched with a mixture of amusement and concern as the tech world tied itself in knots over AI safety. We’ve had more philosophical debates about AI consciousness than I care to remember. Along with endless panels debating whether AI-generated images reinforce harmful stereotypes, executives obsessing over whether chatbots might occasionally be rude, and think tanks treating speculative human extinction scenarios as more urgent than the pressing reality of escalating cyber threats. Whenever the agenda touched on this, AI safety always sucked all the air out of the room, leaving no space for actual security concerns.
I’ll admit I’m deliberately drawing a line between AI safety and security here, even though technically, security has always been stuffed somewhere in the safety umbrella. In the academic literature and in principle, “AI safety” encompasses everything from algorithmic fairness to defense against adversarial attacks. But in practice? Security concerns have consistently been relegated to brief technical asides or hurried final slides in presentations dominated by ethical hand-wringing.
By drawing this line in the conceptual sand, I’m merely making explicit what has already happened implicitly: security considerations have been systematically marginalized in AI governance discussions. When security experts raised concerns at AI safety meetings, they were often treated as those awkward relatives no one invited to the philosophical dinner party. We were those nerds showing pictures of pandas being mistakenly identified as gibbons, wearing horrible sweaters blocking face recognition, and slapping tiny stickers on road signs that could make self-driving cars careen into oncoming traffic – but our warnings about adversarial attacks were treated as curious lab experiments rather than previews of real-world threats. So while I recognize the theoretical unity of these concepts, the practical reality demands we acknowledge the imbalance.
To make matters worse, public AI safety discourse, especially in media headlines, has often been captivated by the idea of superintelligent AI or whether chatbots might “develop feelings”. So, as we’ve been caught in an endless cycle of theoretical discussions about AGI risks, bias in language models, and the eternal question of whether AI will become sentient and take over the world, we spent precious time obsessing over hypothetical threats while ignoring the ones staring us in the face. AI-enabled fraud? Growing by the day. Sophisticated cyber attacks? More common than ever. The disconnect between our focus and reality has been striking.
The AI safety crowd meant well, I’ll give them that. They pushed organizations to think about bias, transparency and ethical implications. But while ethical safeguards are crucial, considering how people’s lives and well-being can be directly affected by AI-driven bias or misinformation, we must balance these concerns with the urgent need to secure AI systems against malicious use. If we don’t, we risk leaving the door wide open for attacks that could harm people far more tangibly than an offensive chatbot ever could.
Security first
I realize that AI safety and AI security are not mutually exclusive. In fact, integrating ethical and bias mitigation measures can help make AI systems more robust against attacks. However, security must take precedence. If AI can be hijacked by malicious actors – whether for fraud, sabotage, or worse – then any well-intentioned safety guidelines become a secondary concern. A transparent model that carefully avoids bias won’t matter if it’s wide open to adversarial manipulation or data breaches.
We need to be crystal clear about the hierarchy of concerns. Security isn’t just a parallel concern to safety, it’s the foundation that makes safety possible in the first place. We can have secure AI systems that haven’t yet addressed all safety concerns, but we simply cannot have truly safe AI without first ensuring its security. This fundamental relationship has been largely absent from public discourse, much to our collective detriment.
By focusing on security first, we establish a stable foundation on which to address broader safety issues. Ethical considerations can still reinforce security, for example, by fostering accountability and transparency that make it harder for attackers to hide malicious activities. But organizations that fail to prioritize security, risk watching their AI systems become tools of harm, eroding both public trust and the very ethical standards they aimed to uphold.
Same old song
The UK’s pivot away from traditional AI safety concerns toward concrete security threats is, in principle, exactly what we need. It’s a recognition that while philosophical debates about AI’s table manners are intellectually stimulating, they don’t address the immediate challenges we face. However, I can’t help but note the irony that it took geopolitical pressure rather than real security concerns to finally make this happen.

What’s troubling isn’t the change itself, it’s the depressingly familiar way it’s come about. This shift appears driven less by a genuine prioritization of security concerns and more by geopolitical and economic anxieties. UK Secretary of State for Science, Innovation and Technology’s emphasis on “unleashing AI and growing the economy” sounds suspiciously like every other tech-related policy shift I’ve witnessed over the past three decades.
We’ve been having this same conversation about every major technological advancement since the invention of the wheel. Remember the internet’s early days, when cybersecurity was an afterthought until viruses and data breaches became commonplace? Or consider the rapid rollout of IoT devices, which prioritized convenience over basic security, leaving millions vulnerable to botnets.
Even smartphones rushed to market without adequately addressing security risks, resulting in scandals that now feel routine. Having watched similar races unfold over the decades, I can tell you exactly how this story usually ends. Spoiler alert: it rarely ends with security winning out over speed to market.
Looking ahead
Despite these questionable motivations, the focus on security is needed more than ever. The UK Institute‘s new mandate to investigate AI’s potential role in chemical and biological weapons development, cyber attacks, and serious crimes like fraud and child exploitation addresses real and pressing threats.
The shift from safety to security, in the end, is the right move, even if it’s happening for the wrong reasons. Will it work? Ask me again in five years. Though I suspect we’ll all be too busy dealing with whatever new crisis has captured the headlines by then to remember this particular policy pivot.
What we need now is a balanced framework that addresses both immediate security threats and longer-term safety challenges. The UK’s pivot toward security could provide this opportunity, and I’m looking at the recently released AI Cyber Security Code of Practice as a step in the right direction, but only if it’s driven by genuine security imperatives rather than just economic expediency.
The Code finally establishes baseline security expectations for AI developers, but voluntary guidelines alone won’t cut it. If this framework is to be more than a press release, it needs teeth, such as clear enforcement mechanisms, industry-wide adoption, and the ability to evolve alongside rapidly advancing threats. Otherwise, we’ll be right back where we started: fussing over AI etiquette while cybercriminals and state actors exploit its vulnerabilities in the real world.
Then again, I’ve seen enough “opportunities” come and go to know that the proof will be in the pudding. And right now, that pudding is still very much in the mixing bowl.