Chronicle/Policy & standards

UK NCSC and US CISA publish multinational Guidelines for Secure AI System Development

PolicyGuidanceSignificance assistant-drafted

The UK NCSC published guidelines for providers of AI systems, developed with CISA and endorsed by agencies from 18 countries. The guidance is organized around four lifecycle areas: secure design, secure development, secure deployment, and secure operation and maintenance, and takes a secure-by-default approach.

Why it matters

It is the baseline multinational government guidance that later AI and agent security documents (the UK Code of Practice, ETSI TS 104 223, the 2026 agentic guidance) build on.

Key facts

As stated in the sources, with where to find them.

  • The guidelines cover four areas: secure design, secure development, secure deployment, and secure operation and maintenance (logging, monitoring, updates, information sharing).Collection overview
  • NCSC describes the guidelines as endorsed by agencies from 18 countries, including the US.NCSC Frontier AI page, related guidance list

Findings that cite this record

No tracked finding cites this record yet.

Sources

Related records