Is Secure by Design mandatory for government AI services?

Contrasting

For central government departments and ALBs, yes — Secure by Design principles are mandatory when delivering digital services and technical infrastructure, and Service Standard point 9 says teams must follow them. They are optional for other parts of the public sector. The AI Cyber Security Code of Practice remains a voluntary industry baseline — use it to deepen practice, not as an opt-out from Secure by Design.

Warning Conflicting or tensioned advice across sources

Secure by Design is mandatory for central government/ALBs. AI Cyber Security CoP is voluntary industry guidance.

How to navigate this: For government services, Secure by Design / Service Manual are the baseline. Use the AI Cyber CoP for additional supply-chain and lifecycle practice.

From the guidance

Primary (how) Secure by Design Principles

As outlined in the Secure by Design policy, these principles are mandatory for government departments and arm’s length bodies (ALBs), and optional for other parts of the public sector.

Contrasting Code of Practice for the Cyber Security of AI

Position: Voluntary code; ‘shall’ means a requirement for the voluntary Code.

Shall Indicates a requirement for the voluntary Code. Should Indicates a recommendation for the voluntary Code.

Related questions