The UK NCSC published guidelines for providers of AI systems, developed with CISA and endorsed by agencies from 18 countries. The guidance is organized around four lifecycle areas: secure design, secure development, secure deployment, and secure operation and maintenance, and takes a secure-by-default approach.
Why it matters
It is the baseline multinational government guidance that later AI and agent security documents (the UK Code of Practice, ETSI TS 104 223, the 2026 agentic guidance) build on.
Key facts
As stated in the sources, with where to find them.
- The guidelines cover four areas: secure design, secure development, secure deployment, and secure operation and maintenance (logging, monitoring, updates, information sharing).Collection overview
- NCSC describes the guidelines as endorsed by agencies from 18 countries, including the US.NCSC Frontier AI page, related guidance list
Findings that cite this record
No tracked finding cites this record yet.
Sources
Related records
Apr 15, 2024
Jun 22, 2026
May 1, 2026
Dec 3, 2025
Jan 4, 2024
May 22, 2025