Should AI products ship with secure-by-default settings?

Answered

Yes. Ideally the most secure setting is the only option. Where configuration is needed, the default should be broadly secure against common threats. Explain riskier capabilities and require opt-in; state what security users are responsible for.

From the guidance

Primary (how) NCSC: Secure deployment (AI systems)

Ideally, the most secure setting will be integrated into the system as the only option. When configuration is necessary, the default option should be broadly secure against common threats (that is, secure by default).

Section: Make it easy for users to do the right things

Read this in NCSC: Secure deployment (AI systems) (opens in new tab)

Related questions