Is Secure by Design mandatory for government AI services?
Contrasting
For central government departments and ALBs, yes — Secure by Design principles are mandatory when delivering digital services and technical infrastructure, and Service Standard point 9 says teams must follow them. They are optional for other parts of the public sector. The AI Cyber Security Code of Practice remains a voluntary industry baseline — use it to deepen practice, not as an opt-out from Secure by Design.
Secure by Design is mandatory for central government/ALBs. AI Cyber Security CoP is voluntary industry guidance.
How to navigate this: For government services, Secure by Design / Service Manual are the baseline. Use the AI Cyber CoP for additional supply-chain and lifecycle practice.
From the guidance
Primary (how) Secure by Design Principles
Section: Overview
Contrasting Code of Practice for the Cyber Security of AI
Section: Terminology
Read this in Code of Practice for the Cyber Security of AI (opens in new tab)
Related questions
- How do teams evidence Secure by Design? Delivery, assurance and operations
- How should commercial teams apply Secure by Design when buying AI? Buying and building
- What is continuous assurance under Secure by Design? Delivery, assurance and operations
- What does Secure by Design expect for detect and respond?
- What does Secure by Design require when buying third-party technology? Buying and building