Guidelines for secure AI system development

The intent of this guidance is to help organisations build cyber security into AI systems from design to deployment.

28 November 2023

The National Cyber Security Centre (NCSC) has joined agencies from 17 countries to release guidance that will help artificial intelligence (AI) developers build in cyber security from the outset.

The United Kingdom’s National Cyber Security Centre led the development of Guidelines for Secure AI System Development, which have been endorsed by 23 international agencies, including New Zealand’s NCSC.

These guidelines are the first of their kind to be agreed globally. They help developers of AI-enabled systems make informed cyber security decisions at every stage of the development process — whether creating new systems from scratch or building on existing tools and services.

Cyber security is an essential precondition for AI system safety. It supports resilience, privacy, fairness, reliability, and predictability. 

Lisa Fong, Deputy Director-General of the National Cyber Security Centre, says: “The guidelines reinforce the need for developers to take a secure by design approach and aim to raise the cyber security of AI systems by helping to ensure that they are designed, developed, and deployed securely.

“Making these guidelines available in collaboration with international partner agencies and industry experts is vital to establishing a common understanding of cyber risks, vulnerabilities, and mitigation strategies.” 

The publication follows the July 2023 release of interim generative AI guidance for the public service. That guidance was jointly produced by the NCSC, as the Government’s system lead for cyber security, alongside our data, digital, procurement, and privacy counterparts, recognising the multidisciplinary approach needed to safely take advantage of generative AI.

Guidelines for secure AI system development [PDF, 2.2 MB]

If you have any questions about this guidance, email the NCSC at info@ncsc.govt.nz.

Related information

Engaging with artificial intelligence

Artificial intelligence (AI) data security

Deploying artificial intelligence (AI) systems securely