The weaponisation of AI in the healthcare sector & the national security risks (UK) Part 3
by Zara Hayat, International Relations Correspondent at Intelligence Forums
Part 3 explores how the weaponisation of AI in the UK healthcare sector becomes a national security risk through the acceleration of cyber disruption, governance weaknesses, and declining institutional trust. It argues that AI-enabled threats are ultimately policy-mediated, emerging from the interaction between hostile actor capability, technological dependence, and fragmented governance rather than from artificial intelligence alone.
Risk Pathway 2: Accelerating disruption to health services
The second way in which artificial intelligence can be weaponised creates national security risks by increasing the speed, scale, and operational feasibility of attacks against healthcare infrastructure. This form does not necessarily target the AI system itself in the same way that AI-specific integrity risks do as discussed in the chapter. Instead, AI functions as a threat multiplier. It enhances existing hostile cyber capabilities making reconnaissance, social engineering, vulnerability exploitation, and post-exfiltration analysis not only faster but more effective. The distinction is important as immediate national security risk may not come from some novel new form of autonomous AI attacks, rather from the acceleration of already familiar cyber threats against a sector whose disruption carries unusually high societal consequences such as healthcare.
The NCSC provides some pertinent assessments that are central to this analysis as they provide concrete UK centric evidence for how AI is expected to alter the threat landscape. The centre argues that in the near term, the impact of AI is likely to be the evolution and enhancement of pre-existing tactics, techniques, and procedures rather than the emergence of entirely new cyber capabilities. This diminishes both technological determinism and speculative alarmism. AI is significant not because it magically transforms all hostile actors into sophisticated cyber powers, but because it can reduce the time, expertise, and costs required to conduct forms of hostile activity. The Centre’s 2025 assessment further expands on this concern by warning that AI-enabled tools such as those that can distort data, create phishing emails and weaken computer systems will with a certainty improve threat actors’ ability to exploit known vulnerabilities, increase the volume of attacks against unpatched systems, and shorten the window between vulnerability disclosure and exploitation. This time constraint is extremely important in the healthcare sector, where cyber resilience is already complicated by legacy systems, intricate procurement structures, and operational pressures.
The WannaCry incident 2017 exposes why this matters. Despite WannaCry not being AI-enabled, the National Audit Office’s investigation provides insights for understanding how cyber disruption translates into consequences for health services. The office reveals that the attack had affected NHS organisations, disrupted appointments and services, and exposed the shortcomings in patching, preparedness, and resilience. The relevance is not that it predicts the exact form that potential future AI-enabled attacks would come in, but that it demonstrates how quickly a technical compromise can become an operational crisis in healthcare. WannaCry like incidents would likely become more common, frequent, targeted and harder to contain if artificial intelligence enables hostile actors to identify exposed systems faster, generate more convincing phishing attempts, automate elements of vulnerability discovery, or scale attack campaigns across multiple organisations.
This is where healthcare differs from other sectors. In this sector disruption to health services produces urgent and immediate individual, organisational and political consequences. Cancelled operations, delayed emergency care, in accessible patient records and diverted ambulances are not just technical failures as they affect the state capacity to protect human life and maintain public confidence. As it translates healthcare disruption into the language of national risk, the inclusion of a cyberattack on the health and social care system in the National Risk Register is significant. It gives heed to the fact that an attack on health infrastructure can generate consequences beyond the affected organisation. This includes but is not limited to degraded service availability, a chain reaction of operational pressures and wider harm to national resilience. These risks are intensified by AI-enabled hostile activities because they have the potential to increase both the likelihood and the tempo of attacks against already strained systems.
Central to the overarching argument is the availability pathway. Availability in this context is the ability of health services to remain operational under adversarial pressure. It is threatened by AI-enabled cyber operations not only through increasing the number of attacks but through changing attacker economics. If artificial intelligence potentially lowers barriers to entry for less sophisticated actors while simultaneously enhancing the efficiency of the more capable groups, the threat environment becomes both broader and more structured. For example, the less capable actors can use AI tools to improve target selection or phishing attacks whilst the more sophisticated actors may combine AI with their pre-existing intelligence capabilities, strategic timing and tailored malware. This can lead to healthcare systems facing higher volume attacks and more carefully calibrated disruption from hostile actors.
The significance to national security lies in the culminated and systemic character of the disruption. This means that a single ransom incident may be treated as an individual cybercrime but repeated or large coordinated disruptions of health services can become a national security problem. During larger periods of crisis such as pandemics, war or mass casualty events healthcare capacity is already under more than average pressure. On top of that, AI-enabled attacks could degrade scheduling systems, logistics, emergency communications, diagnostic access, or patient record availability. This would further undermine the state’s ability to respond effectively and keep mass confidence for the future proving that hostile actors do not need to destroy the health infrastructure in entirely, they may only need to delay distract or destabilise it at moments especially when continuity is essential for it to shake public confidence and create a national security concern.
Nonetheless, we must remain cautious in both writing and drawing conclusions. There is limited observed evidence in regards to large scale AI-enabled attacks against healthcare. Public cyber assessments often discuss AI as an accelerant rather than as a fully autonomous attack capability, and much of the evidence relates to plausible capability uplift. While this could be potentially perceived as a limitation, it does not weaken the argument rather it refines it. The discourse does not surround whether AI guarantees catastrophic disruption, but that it changes the operational conditions under which disruption becomes more plausible and increasingly difficult to manage. National security planning must be concerned with changes in feasibilities, speed and scale. This chapter therefore explored how the weaponisation of artificial intelligence transforms healthcare availability risk by exacerbating hostile actors’ capacity to exploit existing weaknesses. The fear stems not only from the potential for hospitals to be attacked but that attacks may occur faster than institutions and systems can patch, detect or respond. In that sense, AI exposes the security-governance gap at the heart of this piece; healthcare systems are becoming more digitally dependent, while hostile actors are gaining tools that accelerate exploitation faster than policy and resilience frameworks may adapt. The result of this is a shift from isolated cyber incidents to a more strategic and structural problem of national resilience where the healthcare sector becomes a ground through which hostile actors can pressure the state, weaken public confidence, and disrupt essential service delivery.
Risk Pathway 3: Governance failure and strategic exposure
The third and final way AI weaponisation creates national security risk is through governance and trust. This chapter argues that AI-enabled healthcare risk is also produced by the way systems are procured, centralised, legitimised, and governed. The argument becomes not just that hostile actors are exploiting technical vulnerabilities but also whether healthcare institutions create infrastructure that are adequately transparent, accountable, adaptable and trustworthy to withstand adversarial pressure. In this context, governance does not just remain an external response to artificial intelligence risk but becomes part of the security environment itself. The clearest example of this would be the NHS Federated Data Platform controversy. According to NHS England, the platform provides a means to link data across trusts and systems to improve coordination, support clinicians, reduce administrative burdens and enable better use of NHS data. From a purely operational perspective, this is not only understandable but would be beneficial as a fragmented healthcare system can benefit from shared data infrastructures as that can improve visibility, planning and resource allocation. Moreover, Palantir’s involvement caused a controversy. It demonstrates that efficiency-driven data integration can also generate security-relevant concerns. These issues cannot be reduced to the question of whether a certain provider is intrinsically reliable or unreliable. Instead the controversy reveals how decisions around data centralisation, outsourcing, transparency, and accountability shape the conditions under which AI-enabled healthcare systems can become either resilient or strategically exposed.
The concept of centralisation can best depict this duality. A federated data platform can improve coordination by allowing information to flow more effectively across health systems while concurrently creating high-value targets. A healthcare system's vulnerability to disruption, manipulation, or illegal access has a direct correlation to its reliance on centralised analytics, interoperable platforms, and linked data flows. This is especially pertinent in relation to confidentiality. Sensitive health data is not just personal information, it has the capacity to generate strategic value. When compromised it can enable and perpetuate blackmail, coercion, espionage, profiling, or targeted influence operations. In that respect, the Palantir case serves not just as evidence of a confidentiality breach but of a broader governance dilemma. Infrastructure that is supposed to improve healthcare efficiency may also concentrate forms of data value that hostile actors would have incentives to target. Vendor dependence adds a second layer of strategic exposure. In technically complex areas, public-private partnerships are often necessary especially when or where public institutions lack in-house capacity to build large-scale data infrastructure. Reliance or especially over reliance on external providers can complicate accountability, auditability, and long-term resilience. The problem is not just outsourcing rather the extent to which the state retains the meaningful oversight over the systems that become critical to public service delivery. Governance weakness becomes a security problem only if AI-enabled healthcare infrastructures rely on private systems, opaque technical architectures, or outside knowledge that is difficult for public bodies to examine. For instance, a system can be clinically useful and operationally efficient but be increasing institutional dependence on actors, platforms, or supply chains that are difficult to monitor or replace during crisis at the same time.
This is where public trust goes from an ethical concern to a national issue. The success of health systems depends on the public’s willingness to share data, follow advice, and accept institutional decisions especially during emergencies. Even in the absence of technical failure, public confidence can weaken if AI-enabled systems are perceived as opaque, politically contested, or insufficiently accountable. An opening is then created for hostile actors to exploit this mistrust through manipulation, amplifying narratives of surveillance, incompetence or even foreign dependence. An added layer is not only that the misinformation spreads but then it attaches itself to pre-existing governance controversies making legitimacy disputes exploitable vulnerabilities. A technically secure system can still be strategically fragile if the public does not trust the institutions that operate it. The UK’s policy framework, it partially recognises these risks but does not fully integrate them. In line with this, MHRA guidance on software and AI as a medical device depicts an institutional effort to govern AI-enabled clinical safety. Moreover, the UK’s broader pro-innovation approach has also invested efforts into AI regulation and sector-specific governance. However, clinical safety, innovation, and national security resilience are not identical objectives. A system can satisfy clinical safety requirements whilst simultaneously raising questions about data concentration, adversarial manipulation, vendor accountability and public legitimacy. This is reflective of the security governance problem persistent. Artificial Intelligence frameworks tend to focus on safety, ethics, and innovation, while national security frameworks focus on cyber disruption and resilience respectively. The crux of the problem remains that the intersection between these concerns remains underdeveloped. By analysing trust through a socio-technical lens, it becomes evident that public contestation acts as a structural vulnerability; it directly impairs the resilience of the system by degrading its capacity to absorb shocks, while simultaneously undermining the state's securitization efforts by fracturing the domestic legitimacy required for effective crisis governance.
All this leads to the national security implications being culminative. It is governance choices that shape attack surfaces, determines who accesses or controls critical infrastructures, influences how quickly risks can be detected and to what extent the public trusts institutional responses during crisis. If or when hostile actors weaponize AI, it is unlikely that they only rely on one method such as technical intrusion. They would likely combine cyber operations with information manipulation, data exploitation, and strategic efforts to undermine confidence in health institutions. Due to this, trust is not a secondary thought after security, it is one of the conditions that cements resilience. And so this last chapter demonstrates that AI weaponisation in healthcare is best understood as a policy-mediated security problem. The NHS-Palantir does not demonstrate that AI-enabled data infrastructure is inherently dangerous rather demonstrates something analytically more important. It shows that governance arrangements have the capacity to concurrently transform technical systems into strategic assets and strategic vulnerabilities. While centralisation can raise target value, it can also improve coordination. Although it might offer knowledge, outsourcing makes accountability more difficult. Failures in transparency can undermine credibility and provide opportunities for adversarial information operations. It is these dynamics that reaffirm the central argument that AI-related national security risk emerges not from technology alone, but from the interaction between hostile actor capability, institutional design, and contested governance.
AI weaponisation as a policy-mediated national security risk:
The UK's governance architecture was not designed for a threat that lives in the gap between healthcare innovation and national security. The failure is not technical, rather institutional. It emerges through a security-governance gap i.e. a structural misalignment between the way AI-enabled healthcare systems are adopted, governed, and legitimised, and the way national security institutions conceptualise and respond to evolving cyber and AI-enabled threats. The primary finding has been that the weaponisation of AI in the healthcare sector is best understood as a policy-mediated national security risk that continues to be produced through the interaction between hostile actor capability, technological dependence, and fragmented governance.
It connected bodies of literature and evidence that are often fragmented and analysed separately. Those would be themes of AI healthcare governance, cyber and national risk assessments, adversarial machine learning, and public policy theory. In doing so it avoids two common failures: reducing the problem to a technical vulnerability, or inflating AI into a vague strategic threat.
Whilst the article explored the implications specifically through a UK centric lens, the implications can logically transcend borders. Evidently, AI-enabled healthcare systems require not only clinical safety checks, but also security assurance, auditability, data provenance, vendor accountability, and mechanisms for sustaining public trust. This suggests that states cannot treat national security and healthcare AI governance as separate policy conversations and in the long run cannot compartmentalize the threats or the solutions within state borders.
That being said, several limitations still remain. Classified threat intelligence, internal NHS audits, and undisclosed near-miss incidents are missing as reliance remains upon open-source intelligence (OSINT). Attribution is also difficult. The piece focused on risk pathways instead of concrete attributions. The UK focus also reflects a western mindset and English-language bias, although this is justified by the case selection and available evidence base but should not be used to suggest that harm and potential for harm only lies within the west. Lastly, since the Palantir case is politically charged, its use is not to assert unprovable technical claims, but to analyse how trust, centralisation, and legitimacy become security relevant.
In conclusion, the weaponisation of AI against healthcare should not be understood as a distant or purely speculative danger rather an emerging national (and in the long term international) security problem rooted in the current organisation of healthcare infrastructures, the acceleration of hostile capability, and the failure to align AI governance with national resilience. Policy recommendations include but are not limited to mandatory AI security assurance for NHS systems, stronger vendor accountability, adversarial testing, better data provenance rules, NHS-specific AI incident reporting, and closer coordination between DHSC, NHS England, NCSC, MHRA, and Cabinet Office resilience teams.