Who is responsible for security when we use third-party AI components?
Answered
NCSC says providers of AI components should take responsibility for security outcomes of users further down the supply chain — implement controls where possible, use secure defaults, and where risks cannot be mitigated inform downstream users and advise how to use the component securely. Buyers still remain accountable for their own use under Secure by Design and data-protection law.
From the guidance
Primary (how) Guidelines for secure AI system development
Section: Who is responsible for developing secure AI?
Read this in Guidelines for secure AI system development (opens in new tab)
Related questions
- When should we use third-party conformity assessment for AI? Delivery, assurance and operations
- What does Secure by Design require when buying third-party technology?
- How should I handle importing third-party AI models or weights? Security and safe use of tools
- How should I secure the AI supply chain (models and components)? Delivery, assurance and operations
- What are the main security risks of using AI in government? Security and safe use of tools