Skip to main content

Introducing the guidelines for secure AI

New guidelines will help developers make informed decisions about the design, development, deployment and operation of their AI systems.
iStock.com/cnythzl

Artificial Intelligence (AI) systems have the potential to bring many benefits to society. However, for the opportunities of AI to be fully realised, it must be developed, deployed and operated in a secure and responsible way.

On 1st and 2nd November 2023, the UK hosted the first AI Safety Summit which brought together governments, leading technology organisations, academia and civil society to inform rapid national and international action at the frontier of AI development. The summit, building on events across the international community (such as the EU’s AI Act and the G7 Hiroshima AI Process) agreed The Bletchley Declaration. The declaration acknowledges the need for inclusive and collaborative action to address risks around the most advanced and cutting edge ‘frontier’ AI.

On cyber security, the summit stressed the importance of a ‘secure by design’ approach to AI development, which is the key principle behind new Guidelines for secure AI system development, published today by the UK’s National Cyber Security Centre (NCSC), US Cybersecurity and Infrastructure Security Agency (CISA), and 21 other international agencies (listed below).


The Guidelines for secure AI system development are published by the UK National Cyber Security Centre (NCSC), the US Cybersecurity and Infrastructure Security Agency (CISA), and the following international partners:

  • National Security Agency (NSA)
  • Federal Bureau of Investigations (FBI)
  • Australian Signals Directorate’s Australian Cyber Security Centre (ACSC)
  • Canadian Centre for Cyber Security (CCCS)
  • New Zealand National Cyber Security Centre (NCSC-NZ)
  • Chile's Government CSIRT
  • National Cyber and Information Security Agency of the Czech Republic (NUKIB)
  • Information System Authority of Estonia (RIA)
  • National Cyber Security Centre of Estonia (NCSC-EE)
  • French Cybersecurity Agency (ANSSI)
  • Germany’s Federal Office for Information Security (BSI)
  • Israeli National Cyber Directorate (INCD)
  • Italian National Cybersecurity Agency (ACN)
  • Japan’s National center of Incident readiness and Strategy For Cybersecurity (NISC)
  • Japan’s Secretariat of Science, Technology and Innovation Policy, Cabinet Office (CSTI)
  • Nigeria's National Information Technology Development Agency (NITDA)
  • Norwegian National Cyber Security Centre (NCSC-NO)
  • Poland Ministry of Digital Affairs
  • Poland’s NASK National Research Institute (NASK)
  • Cyber Security Agency of Singapore (CSA)
  • Republic of Korea National Intelligence Service (NIS)
  • Cyber Security Agency of Singapore (CSA)

Written by

Claire W NCSC Cyber Policy