New ETSI standard protects AI systems from evolving cyber threats
The NCSC and DSIT work with ETSI to ‘set a benchmark for securing AI’.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening

As with any emerging technology, there's always concern around what this means for security.
The growing deployment and technological advancements of AI systems have the potential to bring many benefits to society, but for these opportunities be fully realised, AI must be developed, deployed and operated in a secure and responsible way.
As the NCSC’s guidance on Secure AI System Development makes clear, artificial intelligence (AI) systems are subject to novel security vulnerabilities – such as prompt injection and data poisoning attacks – that need to be considered alongside standard cyber security threats. This guidance was followed by the UK Department for Science, Innovation & Technology (DSIT) AI Cyber Security Code of Practice, published at the start of 2025. Both documents went through a global consultation process involving industry, international counterparts, academia, and wider civil society.
We’re now pleased to report the publication of two important documents that detail transparent, high-level principles and provisions for securing AI. Published by the European Telecommunications Standards Institute (ETSI), the NCSC and DSIT have worked with other governments, industry leaders and ETSI’s Technical Committee on Securing AI (TC SAI) to produce:
A technical specification on ‘Securing Artificial Intelligence (SAI); Baseline Cyber Security Requirements for AI Models and Systems’.
An accompanying technical report that helps stakeholders implement the cyber security provisions in the above specification, including examples mapped to various international frameworks.
Together, the documents provide stakeholders in the AI supply chain (including developers, vendors, integrators and operators) with a robust set of baseline security requirements that help protect AI systems from evolving cyber threats. These stakeholders may include a diverse range of entities, including large enterprises and government departments, independent developers, small and medium enterprises (SMEs), charities, local authorities and other non-profit organisations. The documents will also be useful for anyone planning to purchase AI services.
The ETSI specification is the first global standard that sets minimum security requirements across the entire AI life cycle for all stakeholders in the AI supply chain. More specifically, it will allow developers of AI systems to demonstrate to prospects and partners that they are adhering to a framework created by cross-disciplinary collaboration, with requirements that are both globally relevant and practically implementable.
The standard defines 13 core security principles grouped into 5 key stages within the AI system development life cycle. These are:
Considering security requirements at all stages of the development life cycle prevents costly redesigns later, and safeguards customers and their data in the near term.
The documents can be downloaded and shared free of charge from the ETSI website. We encourage all developers and the wider supply chain to use the standards to help them build (or evaluate) AI systems that function as intended, are available when needed, and work without revealing sensitive data to unauthorised parties.
The NCSC and DSIT worked with other governments, industry leaders and cyber security experts in the TC SAI to develop the global standard. The UK government will update the content of the Code of Practice and Implementation Guide to mirror the ETSI documents.
The next step is to progress towards a European standard in conjunction with other European and International standards bodies. In practice, European standards are often adopted far more widely than just in Europe. We encourage AI and cyber security stakeholders from across industry, academia and international partners to get involved by visiting the SAI committee page.


