What controls do I need when calling an external AI API?
Answered
Apply controls to data that can leave your organisation — for example requiring users to log in and confirm before sending potentially sensitive information. Prefer departmental assured tools where policy requires it.
From the guidance
Primary (how) NCSC: Secure design (AI systems)
Section: Design your system for security as well as functionality and performance
Read this in NCSC: Secure design (AI systems) (opens in new tab)
Related questions
- Can attackers steal my model or training data through the API?
- Should I use a public AI API, a privately hosted model, or a managed platform?
- How do I stop an AI system from leaking personal or sensitive data?
- Can I put official or unpublished information into public tools like ChatGPT?
- Are AI meeting transcription tools allowed?