Should AI products ship with secure-by-default settings?
Answered
Yes. Ideally the most secure setting is the only option. Where configuration is needed, the default should be broadly secure against common threats. Explain riskier capabilities and require opt-in; state what security users are responsible for.
From the guidance
Primary (how) NCSC: Secure deployment (AI systems)
Section: Make it easy for users to do the right things
Read this in NCSC: Secure deployment (AI systems) (opens in new tab)
Related questions
- Is Secure by Design mandatory for government AI services?
- How do teams evidence Secure by Design? Delivery, assurance and operations
- How should I secure the AI supply chain (models and components)? Delivery, assurance and operations
- What does Secure by Design expect for detect and respond?
- What does NCSC say about securing AI across the life cycle?