Do staff need AI-specific cyber security training?
Contrasting
The voluntary AI Cyber Security Code says organisations’ cyber training shall include role-tailored AI security content. For government services, treat Service Manual / Playbook security obligations as mandatory and use the CoP’s training and lifecycle practices to strengthen that baseline.
AI Cyber Security CoP is voluntary (shall within that frame). Service Manual requires consulting security professionals for AI services.
How to navigate this: Meet mandatory government security practice; use the CoP for detailed AI-specific controls including training.
From the guidance
Primary (how) Code of Practice for the Cyber Security of AI
Section: Principle 1: Raise awareness of AI security threats and risks
Read this in Code of Practice for the Cyber Security of AI (opens in new tab)
Contrasting Service Manual: Using artificial intelligence (AI) in services
Section: Involve cyber security professionals
Read this in Service Manual: Using artificial intelligence (AI) in services (opens in new tab)
Secondary (normative) Code of Practice for the Cyber Security of AI
Section: Introduction
Read this in Code of Practice for the Cyber Security of AI (opens in new tab)
Related questions
- Who should own cyber security risk for an AI service under Secure by Design?
- What are the main security risks of using AI in government? Security and safe use of tools
- Who is responsible for security when we use third-party AI components? Buying and building
- How should I decommission AI models and training data?
- Do AI projects still need to meet the government Service Standard?