The CSBR’s new briefing on the UK cyber skills gap contains one of the sharpest warnings in recent skills policy commentary. It deserves considerably more attention than it is getting.

The CSBR has published a briefing called The UK Cyber Skills Gap: Building Capability and Resilience. Most of it concerns pathways, leadership and organisational capability, and it is a thoughtful piece of work. Within its main themes section, though, sits a single observation that the AICSA believes deserves urgent attention from anyone planning a security workforce.

The briefing puts it plainly. If AI tools automate a growing share of the tasks currently performed by junior analysts, including log analysis, alert triage and initial reporting, demand for entry level cyber roles may fall further, compounding an already thin bottom of the pipeline. It adds that this possibility is not hypothetical, pointing to employer demand for AI related skills in cyber roles rising sharply in 2024. Its conclusion is that policy treating AI purely as an enabler for cyber upskilling, without also assessing how AI reshapes what is being hired for, risks planning for a workforce structure that is already changing.

That is the right warning. It is also not the warning most AI and cyber security conversations are currently having.

The Hourglass and the Machine

The briefing describes the UK cyber labour market as an hourglass: strong demand concentrated at the experienced end of the profession, a thin middle layer of progression opportunities and too few genuine entry routes at the base. The supporting figures given are that in 2024 approximately 17% of core cyber job postings were at entry level while almost two thirds required mid level experience, set against average monthly job postings of around 2,698 and an estimated workforce gap of roughly 3,800 positions.

The briefing’s account of why this structure reproduces itself is the part that matters. Without entry routes there is no pathway to mid level. Without a mid level there is no source of experienced hires. Without experienced hires, organisations raise their requirements further and the entry barrier deepens again.

Now introduce AI at the base of that structure. The tasks AI handles most competently in a security operations context are precisely the tasks that have historically justified hiring somebody with no experience: triaging alerts, correlating log entries, summarising incidents and drafting first pass reports. Those tasks were never especially valuable in themselves. They were valuable because performing them for eighteen months turned a graduate into somebody who could recognise anomalous behaviour by instinct.

If that apprenticeship disappears, the industry does not simply lose a tranche of junior roles. It loses the mechanism by which mid level and senior practitioners were produced in the first place. The effect will not be visible in this year’s vacancy data. It will surface in roughly five years, as a shortage of exactly the experienced people every organisation is already competing for.

What Judgement Costs To Build

The briefing also notes that AI can encourage overreliance when used poorly, and that the AI question is educational and organisational rather than only technical. This is where the AICSA’s position is firmest.

An analyst who has never manually worked through a set of logs has no basis for knowing when an AI generated summary is wrong. The value of a human in an AI assisted security function is judgement about the tool’s output, and judgement of that kind is built by doing the work the tool now does. There is a genuine design problem here that the industry has not solved, and it will not be solved through procurement decisions or through training modules on how to write prompts.

Four approaches are worth testing seriously.

Preserve manual work deliberately, as training rather than as production. If a junior analyst’s role is redesigned around supervising AI output, the organisation should accept that a proportion of their time will be inefficient by design, because that is the time building the competence that makes the supervision meaningful.

Treat the evaluation of AI output as a distinct assessable skill. Recognising a plausible but wrong summary is not the same skill as producing the summary, and it is not currently taught, assessed or credentialed anywhere in a consistent way.

Treat AI adoption in security operations as a workforce planning decision rather than a tooling decision. Organisations deploying AI into their security functions are making a decision about their own future hiring pipeline, usually without realising they have made one.

Measure early career development as an outcome of AI deployment. If nobody is tracking what happens to junior progression after AI tooling lands, the effect will only become visible once it is too late to correct cheaply.

The Gap in the Briefing’s Own Recommendation

The briefing’s first policy recommendation is that the UK should publish a national cyber capability framework distinguishing baseline capability for all staff and leaders, practitioner capability for operational roles and advanced specialist capability for higher risk functions. The AICSA supports that recommendation. It is coherent, it draws sensibly on the NICE Framework and Singapore’s Skills Framework for Infocomm Technology, and it addresses a real and long standing problem.

It is also, as written, silent on AI capability.

A capability framework published now that does not specify what AI competence means at each tier will be describing a workforce that no longer exists by the time employers adopt it. At baseline level, that competence includes understanding what AI assisted attacks look like in practice, including voice cloning and highly personalised phishing generated at scale. At practitioner level, it includes evaluating AI system output critically and understanding the conditions under which models fail. At specialist level, it includes securing AI systems themselves, model and data supply chain risk, and the governance of AI deployed inside the organisation. None of this appears in the tier definitions the briefing proposes.

There is a further point about a workforce category the framework does not yet describe at all. Securing AI systems is not the same discipline as using AI to secure other systems, and neither is well served by role definitions written for a pre generative AI operating environment. Organisations already deploying AI agents with access to internal systems and data are creating an attack surface that very few practitioners have been trained to assess, and no UK framework currently states what competence in that area looks like.

Regulation Will Compete for the Same People

The briefing is also useful on the Cyber Security and Resilience Bill. It argues that expanded regulation creates new demand for compliance and assurance skills at the same time as it places additional burdens on organisations that are already stretched, and that a fragmented regulatory architecture will absorb scarce cyber talent into compliance work rather than resilience work. It recommends the NCSC Cyber Assessment Framework as a common baseline to reduce that duplication.

Add AI governance obligations to that picture and the competition intensifies. The people capable of assessing AI system risk are, at present, largely the same people capable of doing senior technical security work. If regulatory demand and AI assurance demand land on the same small pool simultaneously, organisations will meet their documentation obligations while their actual security posture stands still.

What the AICSA Would Like To See

Four things follow from this briefing that we would like to see taken forward.

First, any national cyber capability framework should specify AI competence at every tier, and should be reviewed on a cycle short enough to keep pace with deployment rather than with legislative timetables.

Second, the entry level effects of AI adoption should be measured directly. Future editions of the Cyber Security Skills in the UK Labour Market research should ask employers whether AI tooling has changed their junior hiring intentions, because at present nobody can say with confidence what the answer is.

Third, employers deploying AI into security operations should be encouraged to publish what they have done to protect early career development, in much the same way they publish diversity data.

Fourth, the securing of AI systems should be recognised as a distinct capability area with its own progression route rather than treated as an assumed extension of existing security roles.

The briefing’s overall conclusion, that the UK has many of the right ingredients and now needs to join them up, is fair and well evidenced. Our concern is one of timing. Joining up a capability system designed around the workforce structure of 2024 will take several years, and that structure is being rewritten right now by tools that were not in production when the underlying research was carried out. The convergence of AI and cyber security is not a future agenda item for skills policy. It is the thing quietly determining whether the pipeline everybody is trying to widen still has a bottom to it.

Read the Report

The UK Cyber Skills Gap: Building Capability and Resilience is published by The CSBR (Cyber Security and Business Resilience) and was released in July 2026. It is available in full at:

Publication page: https://thecsbr.com/research/the-uk-cyber-skills-gap-report/

Direct PDF: https://thecsbr.com/wp-content/uploads/2026/07/CSBR_Cyber-Skills-Gap_Final-1.0.pdf