Skip to content

What you should know about the UK's new cyber standard

28 March 20253 min read
Guest Insights
What you should know about the UK's new cyber standard

On 31 January 2025, the government introduced its Code of Practice for the Cyber Security of AI. Representing a crucial step in creating a secure environment for AI innovation while protecting digital infrastructure from emerging threats.

This initiative comes at a critical juncture in AI development. The technology has become increasingly embedded in critical operations, yet half of UK businesses have experienced a cyberattack in the past year. Establishing a robust security framework has, therefore, become essential for maintaining trust of AI as a transformative technology.

A framework built upon 13 principles

The code is underpinned by 13 software development principles for developers to follow throughout the entire AI system lifecycle. Unlike general software security standards, the code specifically addresses unique AI vulnerabilities including data poisoning, model obfuscation, and indirect prompt injection.

The code will serve as the foundation for a new global standard through the European Telecommunications Standards Institute (ETSI), potentially extending the UK's influence in international AI governance.

A contrasting approach

The UK’s approach contrasts notably with the European Union’s more prescriptive AI Act. Instead of comprehensive legislation, the UK has opted for a principles-based, cross-sector framework that applies existing technology-neutral regulations to AI. This reflects the government’s assessment that while legislative action will ultimately be necessary, particularly regarding general purpose AI systems, acting now would be premature.

This approach aligns with the UK’s broader AI strategy outlined in the AI Opportunities Action Plan, emphasising a pro-innovation regulatory environment designed to attract technology investment while addressing essential security concerns.

The standard supports the UK’s ambition to become a global AI leader. The sector currently comprises over 3,100 AI companies employing more than 50,000 people and contributing £3.7 billion to the economy. The recently launched AI Opportunities Action Plan aims to boost these figures significantly, potentially adding £47 billion annually by increasing productivity up to 1.5% each year.

Not a moment too soon

The code of practice has come in not a moment too soon. Recent research highlights that  approximately 8.5% of employee prompts to popular AI tools contain sensitive information. Of this, customer data accounted for 45% of sensitive information shared, followed by employee data (26%) and legal and financial information (15%). Most concerning for security professionals, nearly 7% of sensitive prompts contained security-related information including penetration test results, network configurations, and incident reports − essentially providing potential attackers with blueprints for exploitation. This is clearly a significant security, compliance, and legal vulnerability for organisations that needs to urgently be plugged.

For businesses looking to implement the standard, the government has published a comprehensive implementation guide to help them determine which requirements apply and provide practical steps for achieving compliance. The guide emphasises the critical importance of advanced governance tracking and AI data gateways to prevent sensitive information exposure to public GenAI models. A necessity highlighted by recent data leakage incidents. Such controls should monitor all AI interactions from employees, contractors, and third parties who might inadvertently share proprietary information.

Fostering innovation

The UK’s new AI standards represent a balanced approach to fostering innovation while addressing security concerns. By providing frameworks that are both comprehensive and flexible, it will help build trust in AI systems and unlock the potential economic benefits.

As AI continues its rapid evolution, a strategic approach favouring guidance and principles over rigid legislation offers businesses the adaptability needed to innovate responsibly. The success of these standards will ultimately depend on their adoption across sectors and how effectively they evolve to address emerging challenges in the increasingly complex AI landscape.

Website: https://www.kiteworks.com/ 

LinkedIn: https://www.linkedin.com/company/kiteworkscgcp/