{"id":463366,"date":"2026-05-01T14:46:14","date_gmt":"2026-05-01T14:46:14","guid":{"rendered":"https:\/\/www.europesays.com\/ie\/463366\/"},"modified":"2026-05-01T14:46:14","modified_gmt":"2026-05-01T14:46:14","slug":"nhs-england-rushes-to-hide-software-over-ai-hacking-fears","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ie\/463366\/","title":{"rendered":"NHS England rushes to hide software over AI hacking fears"},"content":{"rendered":"<p><img decoding=\"async\" class=\"Image\" alt=\"\" width=\"1350\" height=\"900\" src=\"https:\/\/www.europesays.com\/ie\/wp-content\/uploads\/2026\/05\/SEI_295369747.jpg\"   loading=\"eager\" fetchpriority=\"high\" data-image-context=\"Article\" data-image-id=\"2525151\" data-caption=\"Software produced by the National Health Service is usually open to the public\" data-credit=\"Mareks Perkons\/Alamy\"\/><\/p>\n<p class=\"ArticleImageCaption__Title\">Software produced by the National Health Service is usually open to the public<\/p>\n<p class=\"ArticleImageCaption__Credit\">Mareks Perkons\/Alamy<\/p>\n<\/p>\n<p>NHS England is hurriedly withdrawing all the software it has written from public view because of the perceived risk of hacking from cutting-edge artificial intelligence. Security experts say the move is unnecessary and counterproductive.<\/p>\n<p>Software produced by the National Health Service has previously been made open-source and <a href=\"https:\/\/github.com\/nhsengland\" rel=\"nofollow noopener\" target=\"_blank\">listed on GitHub<\/a> because it is created with public money. This allows other organisations to build upon it and make better services more cheaply without duplicating effort.<\/p>\n<p>But NHS England has issued new guidance to staff, which has been shared with New Scientist, that demands existing and future software be pulled from public view and kept behind closed doors. \u201cAll source code repositories must be private by default. Repositories must not be public unless there is an explicit and exceptional need, and public access has been formally approved,\u201d says the new guidance. The deadline for making code private is 11 May.<\/p>\n<p>Last month, an AI created by Anthropic called Mythos was widely reported to be <a href=\"https:\/\/www.newscientist.com\/article\/2524008-do-you-need-to-worry-about-mythos-anthropics-computer-hacking-ai\/\" rel=\"nofollow noopener\" target=\"_blank\">capable of discovering flaws in virtually any software,<\/a> potentially allowing hackers to break into systems running it.<\/p>\n<p>NHS England\u2019s guidance specifically points to Mythos as the cause for the new measures. \u201cPublic repositories materially increase the risk of unintended disclosure of source code, architectural decisions, configuration detail, and contextual information that may be exploited \u2013 particularly given rapid advancements in Al models capable of large-scale code ingestion, inference, and reasoning (e.g. developments such as the Mythos model),\u201d it reads. \u201cThis red line establishes a default-closed posture for code while the organisation assesses the impact of these changes and ensures that any public publication of code is a deliberate, reviewed, and justified decision.\u201d<\/p>\n<p>However, the UK government-backed AI Security Institute (AISI) <a href=\"https:\/\/www.aisi.gov.uk\/blog\/our-evaluation-of-claude-mythos-previews-cyber-capabilities\" rel=\"nofollow noopener\" target=\"_blank\">investigated Mythos<\/a> and found it to be capable of attacking only \u201csmall, weakly defended and vulnerable enterprise systems\u201d, concluding there was no indication that a really secure bit of software or network would be at risk.<\/p>\n<p>The new measures go against the NHS service standard, which demands that staff make any software they produce open-source. \u201cPublic services are built with public money. So unless there\u2019s a good reason not to, the code they\u2019re based [on] should be made available for other people to reuse and build on. Open-source code can save teams [from] duplicating effort and help them build better services faster,\u201d <a href=\"https:\/\/service-manual.nhs.uk\/standards-and-technology\/service-standard-points\/12-make-new-source-code-open\" rel=\"nofollow noopener\" target=\"_blank\">says the previous guidance<\/a>.<\/p>\n<p>Open-source software for public services also creates greater trust and transparency. For instance, if the code for the Horizon IT system that led the UK\u2019s Post Office to <a href=\"https:\/\/www.theguardian.com\/business\/2024\/jan\/07\/what-is-the-post-office-horizon-it-scandal-all-about\" rel=\"nofollow noopener\" target=\"_blank\">pursue innocent people for alleged theft and fraud<\/a> had been public, then the scandal might not have continued for years.<\/p>\n<p><a href=\"https:\/\/en.wikipedia.org\/wiki\/Terence_Eden\" rel=\"nofollow noopener\" target=\"_blank\">Terence Eden<\/a>, who has extensive experience in the UK Civil Service working on opening access to public data, says the move makes no logical sense.<\/p>\n<p>\u201cIs it possible that Mythos will scan a repository and find a bug? Yes, 100 per cent likely. Is that going to be a bug that causes a security issue in a live NHS service somewhere? Almost certainly not,\u201d says Eden. \u201cI think it\u2019s someone in NHS England buying into the hype that Mythos is going to cause the end of security as we know it and getting a bit panicked.\u201d<\/p>\n<p>Eden says open-source software is actually more secure because lots of people can check it for flaws, and most NHS software is not critically related to security in any case. Crucially, given that the code has been publicly available for years, it will continue to exist in various backups and downloads anyway.<\/p>\n<p>\u201cShutting it down now is very much bolting the stable door after the horse has gone,\u201d says Eden. \u201cMyself and the people that I\u2019ve spoken to within the NHS are just completely confused as to what this is trying to achieve.\u201d<\/p>\n<p>A spokesperson for NHS England said: \u201cWe are temporarily restricting access to some NHS England source code to further strengthen cyber security while we assess the impact of rapid developments in AI models. We will continue to publish source code where there is a clear need.\u201d<\/p>\n<p class=\"ArticleTopics__Heading\">Topics:<\/p>\n","protected":false},"excerpt":{"rendered":"Software produced by the National Health Service is usually open to the public Mareks Perkons\/Alamy NHS England is&hellip;\n","protected":false},"author":2,"featured_media":463367,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[261],"tags":[291,289,290,19260,18,19,17,82],"class_list":{"0":"post-463366","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-artificial-intelligence","8":"tag-ai","9":"tag-artificial-intelligence","10":"tag-artificialintelligence","11":"tag-cyberattacks","12":"tag-eire","13":"tag-ie","14":"tag-ireland","15":"tag-technology"},"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@ie\/116499866798107765","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts\/463366","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/comments?post=463366"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts\/463366\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/media\/463367"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/media?parent=463366"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/categories?post=463366"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/tags?post=463366"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}