The UK Government has published the Code of Practice for the Cyber Security of AI, setting baseline security principles for organisations that develop and deploy AI systems.
The Code covers the whole AI lifecycle (secure design, development, deployment, maintenance and end of life) and addresses AI-specific threats, including:
- Data poisoning and model manipulation
- Prompt injection
- Model inversion and extraction
- Supply chain risks in models, datasets and components
Principles include threat modelling, securing training data and models, securing the supply chain, documenting systems and monitoring behaviour.
The Code is voluntary, but it is intended to inform a future global standard through ETSI. It pairs well with ISO/IEC 42001 and ISO/IEC 27001 as part of a joined-up approach to AI governance and security.
Source: AI Cyber Security Code of Practice (GOV.UK)
This update is general information, not legal advice. If you would like help assessing the impact on your information security or privacy programme, contact us.