Chronicle/Policy & standards

UK publishes AI Cyber Security Code of Practice with 13 principles, later standardized as ETSI TS 104 223

PolicyStandardSignificance assistant-drafted

The UK government published a voluntary Code of Practice for the Cyber Security of AI setting 13 principles across five lifecycle phases for developers, system operators and data custodians. It names indirect prompt injection as a distinct AI risk and includes provisions on audit trails, least-privilege access and monitoring system behaviour. ETSI published the content as Technical Specification TS 104 223 in April 2025.

Why it matters

It is a government baseline whose provisions (least privilege, behaviour monitoring, prompt audit trails) map directly onto agent deployments.

Key facts

As stated in the sources, with where to find them.

  • 13 principles across five phases: secure design (4), secure development (5), secure deployment (1), secure maintenance (2), secure end of life (1).Code structure
  • Provision 2.3 requires an audit trail covering operation and lifecycle management of models, datasets and prompts; provision 2.6 limits permissions to those required for functionality.Principles 2 (audit trail, access)
  • Principle 12 asks operators to monitor system behaviour, including internal states where useful, to detect anomalies and unexpected behaviour over time.Principle 12
  • ETSI TS 104 223 (April 23, 2025) expands the 13 core principles into 72 trackable principles and lists indirect prompt injection among covered threats.ETSI press release

Findings that cite this record

No tracked finding cites this record yet.

Key questions this bears on

Sources

Related records