Published: 22 July 2025
Facing Up to AI Security
š§ Securing the Future: A CISOās Guide to the UK AI Cyber Security Code of Practice
As AI becomes embedded in everything from finance to national infrastructure, the risks it introducesāboth to and through cyber systemsāare evolving at pace. To help manage these risks, the UK government recently published the AI Cyber Security Code of Practice, a voluntary guide aimed at improving how AI systems are developed, deployed, and defended.
But what does this mean for CISOs and cybersecurity teams? How useful is the Code in real-world applications, and where might it fall short?
š What Is the AI Cyber Security Code of Practice?
The UKās AI Cyber Security Code of Practice is a voluntary framework designed to help developers and operators secure AI systems throughout their lifecycle. It aligns with existing cybersecurity standards (like NIST and ISO 27001) while addressing emerging risks unique to AI technologies.
The Code is built around five core principles:
- Secure AI Development
- Secure AI Deployment
- Secure Supply Chain
- Technical and Organisational Governance
- Continuous Risk Management
ā Benefits for CISOs and Security Leaders
1. Structured Security Framework
The Code provides a clear, repeatable structure for managing AI-specific cyber risks and integrating AI security into broader enterprise strategies.
2. Supply Chain Risk Awareness
It emphasizes the importance of vetting and securing third-party AI components, APIs, and training datasets.
3. Governance and Risk Ownership
Encourages defined roles and responsibilities for AI security, improving cross-team governance.
4. Continuous Threat Monitoring
Promotes real-time model monitoring to detect drift, bias, or adversarial threats early.