What controls do I need when calling an external AI API?

Answered

Apply controls to data that can leave your organisation — for example requiring users to log in and confirm before sending potentially sensitive information. Prefer departmental assured tools where policy requires it.

From the guidance

Primary (how) NCSC: Secure design (AI systems)

if using an external API, you apply appropriate controls to data that can be sent to services outside of your organisation’s control, such as requiring users to log in and confirm before sending potentially sensitive information

Section: Design your system for security as well as functionality and performance

Read this in NCSC: Secure design (AI systems) (opens in new tab)

Related questions