Who is responsible for security when we use third-party AI components?

Answered

NCSC says providers of AI components should take responsibility for security outcomes of users further down the supply chain — implement controls where possible, use secure defaults, and where risks cannot be mitigated inform downstream users and advise how to use the component securely. Buyers still remain accountable for their own use under Secure by Design and data-protection law.

From the guidance

Primary (how) Guidelines for secure AI system development

As such, in line with ‘secure by design’ principles, providers of AI components should take responsibility for the security outcomes of users further down the supply chain.

Section: Who is responsible for developing secure AI?

Read this in Guidelines for secure AI system development (opens in new tab)

Related questions