Ofcom has opened a round of closed-door conversations with telecoms operators and technical specialists on how artificial intelligence is deployed to detect intrusions, patch vulnerabilities, and keep critical voice and data networks online. The regulator said it will examine whether compliance duties under the Telecommunications (Security) Act 2021 and the Network and Information Systems Regulations 2018 accidentally discourage adoption of defensive models that could shrink mean-time-to-recovery after attacks.
Closed engagement, public stakes
Ofcom has not opened a standard public consultation on this slice of work; LexisNexis and MLex both describe closed sessions with operators and technical experts through autumn 2026. That format lets carriers share sensitive telemetry without tipping attackers, but it also means smaller suppliers must rely on trade associations to surface barriers second-hand.
Why the review landed now
MLex reported on 22 September that the media and telecoms watchdog plans months of expert sessions, with scope to widen into broader AI risk questions if evidence points that way. LexisNexis Legal News, publishing a day earlier, framed the work as an industry engagement on assurance, accountability, vendor oversight, and regulatory barriers across critical communications. Findings are slated for early 2027, a timeline that could feed both Ofcom guidance and government cyber policy as the Cyber Security and Resilience Bill advances.
Ofcom's own strategic approach to AI for 2026/27 already sketches parallel research tracks labelled "AI for Networks" and "Networks for AI." The former probes fault prediction, performance management, and explainability expectations inside carriers; the latter asks what connectivity, capacity and coverage operators must deliver as AI services scale across the economy. Cyber security sits at the intersection—models that automate threat hunting also need audit trails regulators can inspect.
TSA and NIS as the baseline
UK telecom security rules were tightened after the 2021 TSA amendments to the Communications Act, giving Ofcom powers to set binding security frameworks and fine firms up to 10% of turnover for serious breaches. NIS, meanwhile, covers digital infrastructure beyond classic telcos. Operators often run the same security operations centre for both regimes, yet AI procurement policies differ: some legal teams treat opaque models as incompatible with demonstrable control obligations.
What vendors will be asked
Expect questions on training data provenance, human override paths, and how third-party SaaS models sit inside regulated supply chains. Closed engagement does not mean secret lawmaking; it signals that Ofcom is gathering commercially sensitive deployment detail it does not want aired in open consultation comments. Carriers that already use machine learning for signalling anomalies may be asked to evidence false-positive rates and staff training—metrics that could later appear in formal guidance.
Vendor assurance questions
Carriers buying security models from hyperscalers will likely be asked how they retain logging when a vendor updates weights silently, and whether human analysts can explain a block decision to Ofcom examiners. Those are not abstract ethics debates; they decide if automated triage counts as meeting TSA duties to protect signalling data. Operators that experimented during the 2024–2025 ransomware wave may already have incident data Ofcom wants behind closed doors.
Link to wider UK AI governance
The review sits downstream of frontier-model debates in Westminster but upstream of customer-facing harms. If defensive AI is bottlenecked by paperwork, attackers who face no procurement committee will keep the advantage. Early 2027 findings should clarify whether Ofcom will publish expectation statements under TSA codes or push ministers for legislative tweaks. Until then, network security architects should document every pilot: the engagement is as much about proving what already works as about hunting barriers that exist only on paper.
Ofcom's published AI strategy for 2026/27 already lists case study work on AI for networks and networks for AI, signalling that defensive cyber tooling will be judged alongside capacity planning for AI traffic. Operators should expect questions on whether automated blocking violates transparency duties when customers lose service.








