Do AI projects still need to meet the government Service Standard?
Answered
Yes. AI services must meet the same standards as other technology. Service Standard point 9 requires Secure by Design principles. Central government departments and ALBs must meet the Secure by Design policy when delivering digital services and technical infrastructure. Follow Secure by Design / Service Manual security expectations — including consulting security professionals for AI.
From the guidance
Primary (how) Service Manual: Using artificial intelligence (AI) in services
Section: Using artificial intelligence (AI) in services
Read this in Service Manual: Using artificial intelligence (AI) in services (opens in new tab)
Secondary (normative) Technology Code of Practice
Section: 13. Meet the Service Standard
Secondary (normative) AI Playbook for the UK Government
Section: Principle 5: You understand how to manage the full AI life cycle
Read this in AI Playbook for the UK Government (opens in new tab)
Secondary (normative) Service Manual: Using artificial intelligence (AI) in services
Section: Involve cyber security professionals
Read this in Service Manual: Using artificial intelligence (AI) in services (opens in new tab)
Secondary (normative) About Secure by Design
Section: Secure by Design’s wider context
Secondary (normative) Implementing Secure by Design
Section: Implementing Secure by Design
Read this in Implementing Secure by Design (opens in new tab)
Related questions
- Which organisations must use the Algorithmic Transparency Recording Standard? Lawful, ethical and responsible use
- Who should own cyber security risk for an AI service under Secure by Design?
- Do I need to tell users when a service uses AI?
- How should I secure the AI supply chain (models and components)?
- How do teams evidence Secure by Design?