{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/uk-ai-cyber-security-code-of-practice-2025/",
 "asOf": "2026-09-26",
 "id": "uk-ai-cyber-security-code-of-practice-2025",
 "date": "2025-01-31",
 "datePrecision": "day",
 "title": "UK publishes AI Cyber Security Code of Practice with 13 principles, later standardized as ETSI TS 104 223",
 "lane": "policy",
 "kind": "standard",
 "summary": "The UK government published a voluntary Code of Practice for the Cyber Security of AI setting 13 principles across five lifecycle phases for developers, system operators and data custodians. It names indirect prompt injection as a distinct AI risk and includes provisions on audit trails, least-privilege access and monitoring system behaviour. ETSI published the content as Technical Specification TS 104 223 in April 2025.",
 "whyItMatters": "It is a government baseline whose provisions (least privilege, behaviour monitoring, prompt audit trails) map directly onto agent deployments.",
 "actors": [
  "uk-dsit",
  "etsi"
 ],
 "topics": [
  "standards-and-guidance",
  "prompt-injection",
  "monitoring-and-control"
 ],
 "atlas": [
  "untrusted-content",
  "credentials",
  "monitor"
 ],
 "artifacts": [],
 "sources": [
  {
   "url": "https://www.gov.uk/government/publications/ai-cyber-security-code-of-practice/code-of-practice-for-the-cyber-security-of-ai",
   "publisher": "GOV.UK",
   "title": "Code of Practice for the Cyber Security of AI",
   "date": "2025-01-31",
   "type": "primary",
   "accessed": "2026-09-25"
  },
  {
   "url": "https://www.etsi.org/newsroom/press-releases/2521-etsi-technical-specification-sets-international-benchmark-for-securing-artificial-intelligence",
   "publisher": "ETSI",
   "title": "ETSI Technical Specification sets international benchmark for securing Artificial Intelligence",
   "date": "2025-04-23",
   "type": "primary",
   "accessed": "2026-09-25"
  }
 ],
 "keyFacts": [
  {
   "fact": "13 principles across five phases: secure design (4), secure development (5), secure deployment (1), secure maintenance (2), secure end of life (1).",
   "locator": "Code structure"
  },
  {
   "fact": "Provision 2.3 requires an audit trail covering operation and lifecycle management of models, datasets and prompts; provision 2.6 limits permissions to those required for functionality.",
   "locator": "Principles 2 (audit trail, access)"
  },
  {
   "fact": "Principle 12 asks operators to monitor system behaviour, including internal states where useful, to detect anomalies and unexpected behaviour over time.",
   "locator": "Principle 12"
  },
  {
   "fact": "ETSI TS 104 223 (April 23, 2025) expands the 13 core principles into 72 trackable principles and lists indirect prompt injection among covered threats.",
   "locator": "ETSI press release"
  }
 ],
 "significance": 3,
 "fideQuestions": [],
 "methods": [
  "ai-monitoring",
  "capability-restriction",
  "indirect-prompt-injection"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}