• Sectors we work in banner(2)

    Quick Reads

New code of practice for the cyber security of AI development

 

Developers of AI systems are now encouraged to follow a voluntary Code of Practice (the Code) that sets baseline security requirements, addressing the cyber security risks to AI.   The Code will be used to create a global standard in the European Telecommunication Standards Institute (ETSI).

The scope of the voluntary Code of Practice is focused on AI systems. This includes systems that incorporate deep neural networks, such as generative AI. The Code is not intended for academics who are creating and testing AI systems only for research purposes but will apply to those who create AI systems such as bots from generative AI models. 

The Code sets out cyber security requirements for the lifecycle of AI and identifies five development phases. These are design, development, deployment,  maintenance and end of life.   The code focuses on all stakeholders in these phases, namely developers, system operators, data custodians and end users.  Covering each phase are a series of 13 principles ranging from ‘raise awareness of AI security threats and risks’ at the beginning of the lifecycle, to ‘securing your supply chain and conduct appropriate testing and evaluation to ensuring proper data and model disposal’ at the end.

Whilst voluntary, the code aims to support the security and safety of AI systems designed, developed and deployed in the UK.  It is expected that this code will become more widely adopted if it forms part of the ETSI standard. 

Full details of the code can be found here:  Code of Practice for the Cyber Security of AI - GOV.UK

Our thinking

  • The Playbook to Superscale: Hacks 1-3

    Events

  • From Prime Time to Match Day: Engaging the Female Audience

    Events

  • Women in Leadership: In conversation with Wendy Edwards and Karen Ellis

    Claudine Morgan

    Events

  • Corporate restructuring: Preparing for Future Challenges

    Shirley Fu

    Insights

  • Choosing the Right PISCES Platform for Private Company Liquidity

    Greg Stonefield

    Insights

  • How to construe contentious trusts - lessons from recent cases

    Sarah Moore

    Insights

  • Q&A: Modifying Restrictive Covenants

    Chandni Pandya

    Insights

  • Grid Connections, Environmental Assessment and the DCO Process – What is the effect of the Raeshaw Farms judgement?

    Kevin Gibbs

    Insights

  • Construction News and Facilities Management Now quote William Turner, Elizabeth Hughes, and Alexander Hemmings on new Construction Industry Scheme rules for supply chain fraud

    Elizabeth Hughes

    In the Press

  • Eddie Richards and Sadie Pitman write for Logistics Business on the UK's readiness for an electric vehicle revolution

    Sadie Pitman

    In the Press

  • Chiara Muston comments in People Management on 'empty time' and the gig economy

    Chiara Muston

    In the Press

  • Q&A: Boundary Issues

    Emma Preece

    Insights

  • Remedy and Leverage: Addressing Human Rights Risks in Corporate Supply Chains

    Kerry Stares

    Insights

  • Charles Russell Speechlys Partner Promotions 2026

    Bart Peerless

    News

  • How is the UK Construction Industry Impacted by Modern Slavery?

    Henry Dalton

    Insights

  • Application for modification of restrictive covenant fails on “worst case” scenario

    Georgina Muskett

    Insights

  • IFLR interviews Jean-Baptiste Beauvoir-Planson on our role advising the first PISCES share sale

    Jean-Baptiste Beauvoir-Planson

    In the Press

  • Social risks in the supply chain – from due diligence to resilience: Corporate human rights due diligence – a snapshot of the law in EU/UK

    Kerry Stares

    Podcasts

  • Time to Pay Up: The Government Responds to the Late Payments Consultation

    Willemijn Paul

    Quick Reads

  • The 1975 Act 50 Years On: Looking Back and Looking Forward

    Tamasin Perkins

    Insights

Back to top