NHS England is reportedly departing from its long-standing policy that mandates all software developed using public funds be made publicly accessible. This significant shift in approach is understood to be a direct response to escalating concerns over the potential for sophisticated artificial intelligence (AI) models to be leveraged for cyber-attacks, specifically naming advanced systems like 'Mythos'.
Historically, the National Health Service has championed transparency and open innovation, with rules designed to ensure that tools created with taxpayer money could benefit the wider public and foster collaborative development. This principle meant that the underlying code for various NHS-developed applications and systems would typically be made available for scrutiny and use, aligning with broader governmental pushes for open data and open-source solutions.
However, the emergence of highly capable AI models capable of rapidly identifying vulnerabilities and automating hacking attempts has reportedly prompted a re-evaluation of this policy. Sources suggest that the NHS leadership believes that making software code publicly available could inadvertently create a roadmap for malicious actors, particularly those employing advanced AI, to exploit weaknesses within critical health infrastructure.
The decision to conceal software, rather than adhere to the previous open-source mandate, highlights a growing tension between the benefits of transparency and the imperative for robust cybersecurity in an increasingly digitised world. While open-source development can lead to more secure and innovative software through community scrutiny, the perceived threat from AI-powered hacking appears to have tipped the balance towards a more closed approach for sensitive systems within the NHS.
This policy change could have broad implications for how future digital tools are developed and deployed across the NHS. It raises questions about the balance between fostering innovation through openness and ensuring the security of vital public services against evolving cyber threats. The exact scope and criteria for which software will now be withheld from public view remain to be fully clarified.