NHS England is facing growing opposition over its decision to remove its open-source software from public access, citing fears that advanced artificial intelligence models could exploit vulnerabilities. The move, intended to bolster cybersecurity against sophisticated threats such as 'Mythos', has sparked a backlash from transparency advocates, technology experts, and those within the digital health community.
The software in question is understood to be the underlying code that powers the NHS website and its official app, both crucial platforms for millions of UK citizens to access health information and services. Open-source software, by its nature, allows anyone to view, modify, and distribute its code. Proponents argue this fosters collaboration, identifies bugs more quickly, and promotes innovation, while detractors of the NHS's current plan suggest that removing public access could ironically make the system less secure by limiting external scrutiny.
Critics contend that hiding the source code will do little to deter determined cyber attackers, especially those utilising highly advanced AI models. They argue that sophisticated malicious actors could still reverse-engineer the software or discover vulnerabilities through other means, while the public withdrawal simply removes the benefit of a vast community of developers who might otherwise identify and report flaws. This approach, they suggest, runs counter to best practices in cybersecurity, which often advocate for 'security through transparency' rather than 'security through obscurity'.
Furthermore, concerns have been raised about the impact on transparency and efficiency. Many believe that public access to the code is vital for accountability and for independent developers to build compatible tools or suggest improvements. Limiting this access could stifle innovation and make it harder for the public and oversight bodies to understand how critical national health infrastructure operates, potentially hindering the NHS's ongoing digital transformation efforts.
This decision by NHS England comes at a time of heightened awareness regarding cybersecurity threats, particularly those leveraging AI. However, the debate underscores a fundamental tension between perceived immediate security benefits and the long-term advantages of open collaboration and transparency in public sector digital initiatives. The outcome of this debate could set a precedent for how other critical national infrastructure projects manage their digital assets in an increasingly AI-driven threat landscape.