The UK government published a voluntary Code of Practice for the Cyber Security of AI setting 13 principles across five lifecycle phases for developers, system operators and data custodians. It names indirect prompt injection as a distinct AI risk and includes provisions on audit trails, least-privilege access and monitoring system behaviour. ETSI published the content as Technical Specification TS 104 223 in April 2025.
Why it matters
It is a government baseline whose provisions (least privilege, behaviour monitoring, prompt audit trails) map directly onto agent deployments.
Key facts
As stated in the sources, with where to find them.
- 13 principles across five phases: secure design (4), secure development (5), secure deployment (1), secure maintenance (2), secure end of life (1).Code structure
- Provision 2.3 requires an audit trail covering operation and lifecycle management of models, datasets and prompts; provision 2.6 limits permissions to those required for functionality.Principles 2 (audit trail, access)
- Principle 12 asks operators to monitor system behaviour, including internal states where useful, to detect anomalies and unexpected behaviour over time.Principle 12
- ETSI TS 104 223 (April 23, 2025) expands the 13 core principles into 72 trackable principles and lists indirect prompt injection among covered threats.ETSI press release
Findings that cite this record
No tracked finding cites this record yet.
Key questions this bears on
- Can prompt injection against AI agents be reliably defended?Not reliably. Defenses reduce injection but none has eliminated it; limiting what untrusted input can trigger is the most defensible approach.
- Can AI agents defend and oversee systems on their own?Not yet. Agents are weak on realistic defensive benchmarks and monitors can be evaded; assistants help analysts who stay in charge.
Sources
Related records
Jun 3, 2026
Jul 16, 2025
May 6, 2025
Mar 24, 2025
May 15, 2026
Jan 8, 2026