UK Government publishes new policy paper: Code of Practice for the Cyber Security of AI
6th May 2025
As part of an intervention to address cybersecurity risks posed by AI, the Department for Science, Innovation and Technology (DSIT), as part of the UK Government, has published a code of practice that sets baseline security requirements for AI systems. This is a voluntary code of practice for developers, organisations, system operators, data custodians and end users. It includes guidance on making software secure by design and advises on the security requirements needed to protect AI systems from design and development to deployment and maintenance. This code aims to provide security for AI systems and the organisations using them, while allowing for innovation. This code is intended to form a basis for a new global standard of security for AI technology.
What does this Code of Practice contain?
There are 5 separate phases divided into 13 principles in this code of practice that span the entire lifecycle of AI technology, from training and development to testing and deployment, all the way to end-of-life data and model disposal. Here are the five phases:
Design
Security measures should be included from the very beginning at the design stage of AI technologies. Systems should be designed with cybersecurity in mind and should be able to withstand cyberattacks and potential breaches. Data Custodians should be involved at this stage to ensure that systems are designed as intended without unnecessary functionality that could jeopardise security. Organisations should plan regular training and threat modelling that includes AI security content, and update their training programmes as and when new security threats emerge. All AI systems should be designed to enable human responsibility, incorporating and maintaining capabilities for human oversight.
Note: ‘Data Custodian’ refers to any business, organisation or individual that controls data permissions and data integrity when used for an AI model or system. There could be multiple Data Custodians involved.
Development
During the development phase, Developers should evaluate potential threats and risks to AI systems. All developers, data custodians and System Operators should be able to track their AI assets, including training and test data, models, and infrastructure, to prevent any unauthorised access. Sensitive data used for training AI models should be protected appropriately. When developing AI models and systems, all developers and operators should follow secure software supply chain processes. Documentation should be provided, including all security-relevant information, and made available to System Operators and end users.
Note:
‘Developers’ in this context refers to any businesses, organisations or individuals responsible for creating or adapting an AI model and/or system.
‘System Operators’ in this context means any business or organisation that is responsible for embedding or deploying an AI model and system within their infrastructure.
‘End users’ refers to any employees of organisations or businesses that use AI models or systems for any purpose, including for work or day-to-day activities.
Deployment
Human involvement is essential at this stage for oversight of AI systems, risk management and ongoing monitoring of systems. Staff training should include details on how to use the system, security awareness, including risk reporting, and business continuity plans should be created in the case of any problems. Guidance should be provided on how to use AI models and systems appropriately, including potential limitations and failures. All AI systems should be compliant with all data protection legislation while the system is in use. End users should be informed how their data is used, stored and accessed.
Maintenance
Developers should provide security patches and updates for AI systems, and system operators should be notified and deliver updates to end users. All major system updates should be treated as new versions and should be tested thoroughly before going live. System operators should log all system and user actions, monitor the performance of the models and systems over time, and analyse data logs to ensure AI software continues producing the desired outputs and has not experienced anomalies, unexpected behaviours or potential security breaches.
End of Life
If an AI system or model is decommissioned or ownership is transferred, data custodians should make sure that all relevant data, assets and configurations are correctly dealt with and securely deleted or disposed of.
This code could be a welcome development and a proactive step towards helping businesses protect personal data while still enjoying the benefits of AI. As a voluntary code, it will be interesting to see how many organisations choose to implement it.
Some key principles of the GDPR include lawfulness, transparency, data minimisation, accuracy, security and storage limitation. Any AI system must allow a user to be compliant with the GDPR and so users must be able to know from where data has originated, what was the lawful basis of processing (for example, has any intellectual property rights or copyright been infringed), how can users ensure the information is accurate and AI has not hallucinated? And more information than is strictly necessary has not been captured. Users must also be able to delete information and anonymise or pseudonymise records, hiding the identity of individuals. Finally, how will users inform data subjects how the data will be used and for what purpose if they do not know themselves?
It is crucial that users understand how AI systems work in principle and can set parameters. For example, will data be processed locally or sent to a server? How will user data be processed, and with which third parties will it be shared? Users must not only consider personal data but also commercially sensitive company data.
If you are using AI systems in your workplace or plan to in the near future, we would advise familiarising yourself with the Code of Practice, and if you have any questions or concerns, feel free to get in touch with us. You can contact the team at Griffin House here or call us at 01673 885533.
Author: Mike Martin LLM
Mike is an information governance specialist and one of the founding Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.
Sources