ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

UK cyber-regulation: clear and simple or just unreadable?

Fergal McGovern at VisibleThread explores the readability problem hiding in UK government cyber guidance

Cyber-security is critical to national security, and the UK is producing more cyber-security guidance with which organisations are expected to comply. From the expanded NIS regime to Martyn’s Law and the Cyber Security and Resilience Bill, the message from the government is clear: organisations are expected to be more resilient, respond more quickly and take greater responsibility. 

 

It’s hard to argue with the need for the new measures. However, there is a problem hiding in plain sight. 

 

Too often, the way this guidance is written makes compliance more difficult than it should be.

 

If security teams cannot quickly understand what a policy means, they cannot reliably implement it. If legal, compliance, procurement and technical teams all read the same document differently, the levels of compliance go down and improvising goes up.

 

When it comes to cyber-security, the gap between the intention of new policies/bills and how they’re executed in real life is where risk grows. 

 

AI can help, but only if it is safe

This is where the conversation gets confusing. And where a lot of vendors are not being straight with you.

 

There’s no doubt AI can help teams work through dense regulatory text faster. AI can also:

  • Flag long sentences.
  • Suggest clearer phrasing.
  • Standardise language across documents.
  • Reduce review time. 

Busy teams will immediately recognise these benefits. However, there is a version of AI being sold that is not fit for the compliance use case. Organisations need to understand why. Generative AI is probabilistic. If you ask the same question twice, you’ll get two different answers.

 

This isn’t a bug. It’s the way large language models are designed to work. This variability isn’t a problem when it comes to drafting, summarising or sense-checking a document. But we run into hot water when it comes to the other tasks. 

 

If you are identifying whether a specific requirement appears in a document, you need 100% accuracy and 100% repeatability. This is the same if you’re checking whether a clause creates contractual exposure. And likewise to check whether a submission meets every requirement in an RFP. 

 

These tasks require rules-based, deterministic logic. Not the best prediction an AI tool can make.

 

We also need to address data quality. AI treats every word in a document in the same way. It has no ability to distinguish a policy document updated last month from a guidance note written four years ago that has since been superseded.

 

If you point AI at a large SharePoint environment or a folder full of documents, all will be processed with equal weight. That means that an outdated framework could sit along current, approved content. The AI tool will not flag the difference. This is a problem. And it matters hugely in a regulatory context. 

 

Messy inputs lead to messy outputs. Worst of all, you may not always know this has happened until the problem surfaces somewhere inconvenient.

 

What good looks like

So where can AI actually help?

 

You need a system that is always right for accuracy-critical jobs, such as:

  • Identifying specific requirements.
  • Flagging contractual terms.
  • Checking for watchwords.
  • Verifying that every obligation has been captured.

These are the tasks where deterministic, pattern-matched logic is non-negotiable. It’s at this point AI can be introduced to the task. If the content has been accurately identified and scoped, AI can then help interpret, summarise and surface meaning from it. But it’s critical that AI is being pointed at the right content in the first place.

 

You have to be deliberate about which documents you’re using as inputs. Don’t assume the model will figure out which parts of your knowledge base to use. This assumption could lead to a massive problem with huge consequences.

 

Deterministic AI will also be able to show teams responsible for government-facing work what was reviewed, or changed, and why. This is a basic accountability requirement.

 

Readability is a cyber-security issue

Government needs to think about readability differently. We have expectations for things to be tested.  We expect cyber-security controls to be tested. We audit systems. We assess risk. Yet we seldom apply that same discipline to the documents that define the obligations in the first place. This has to change. 

 

Readability is not a marketing “nice to have”. It’s essential for documents to be usable. If a regulation is not understood by its intended audience, it’s not fit for purpose.

 

What security leaders should do

There’s no benefit in treating clunky guidance as nothing more serious than an annoyance. It’s an implementation risk.  It won’t help to throw AI at policies and hope for the best. Instead, guidance needs to be made usable in your organisation.

 

All of this new policy and guidance is being created to increase the UK’s cyber-resilience. Therefore, it’s necessary to place an important focus on readability.

 

And finally, we have to interrogate the AI tools we’re using to understand which ones are actually suitable for the compliance task.

 


 

Fergal McGovern is the founder of VisibleThread, a secure AI platform

 

Main image courtesy of iStockPhoto.com and fizkes

Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543