AI security is the focus of new guidelines developed by the UK's National Cyber Security Centre (NCSC) and the US Cybersecurity and Infrastructure Security Agency (CISA). Their central message is that cybersecurity should be considered from the beginning of an AI project and carried through its development and use.
A life-cycle approach to AI security
The document, called the “Guidelines for Secure AI System Development,” is intended to help AI developers make informed cybersecurity decisions at each stage of building a system. It applies to systems created from scratch as well as those that rely on third-party tools and services.
The guidelines promote “security by design”: treating security as a core requirement from the outset, rather than adding it after development. The stated aim is to improve cybersecurity across AI design, development, and deployment.
This approach connects choices made early in a project with the work needed to protect and maintain a system later. For teams, it means considering risks and protections as part of the development process, including when outside services or tools form part of the system.
Four areas for practical guidance
The recommendations are organized into four areas: secure design, secure development, secure implementation, and secure operation and maintenance. Together, they cover planning and building a system as well as putting it into use and managing it over time.
- Secure design and development: Understand risks, use threat modeling, consider supply chain security, and document the system.
- Secure implementation: Protect infrastructure and models, prepare for incident management, and consider responsible release.
- Secure operation and maintenance: Use logging and monitoring, manage updates, and share information.
The areas span decisions that can otherwise sit with different teams. Design and development address how a system is planned and assembled; implementation focuses on protections and incident handling as it is put into use. Operation and maintenance keep attention on security after that point.
International participation
NCSC developed the guidelines in collaboration with CISA. Industry experts and 21 other international agencies and ministries also took part in drafting them, including participants from all members of the G7 and the Global South.
The source reports that 17 other countries, including the United States, pledged support and participation. It also names international signatories: Australia, Canada, Chile, Czech Republic, Estonia, France, Germany, Israel, Italy, Japan, New Zealand, Nigeria, Norway, Poland, Singapore, South Korea, the United Kingdom, and the United States.
NCSC Chief Executive Lindy Cameron called the guidelines “a significant step in shaping a truly global, common understanding of the cyber risks and mitigation strategies around AI to ensure that security is not a postscript to development but a core requirement throughout.” The statement reflects the document's emphasis on making cybersecurity part of AI work throughout the process.
What the recommendations mean for developers
The framework presents security as a continuing responsibility: developers are asked to consider risks, documentation, infrastructure, models, incidents, monitoring, and updates across a system's life cycle. Its inclusion of third-party tools and services also makes supply chain security part of the picture.
The guidelines offer recommended behaviors rather than a single technical measure. Their structure gives teams a way to consider security at multiple points, from the initial design through ongoing maintenance, with the goal of building and operating AI systems more securely.