UK-native guidance
The UK's AI Cyber Security Code of Practice, explained
In January 2025 the UK government published a voluntary Code of Practice for the cyber security of AI: principles for securing AI systems across their whole life, from first design to final decommissioning. Here is what it covers, who should be following it, and why voluntary does not mean ignorable.
The essentials
What the Code is and who publishes it
The Code of Practice for the Cyber Security of AI comes from the Department for Science, Innovation and Technology (DSIT). It sets out security principles for AI systems, organised around the stages of the AI lifecycle, and it is deliberately voluntary: guidance for organisations to adopt, not law to comply with. The canonical text lives on gov.uk.
Its ambition is bigger than a UK document, though. The government's stated intent is for the Code to seed an international standard through ETSI, the European standards body. Adopting it now means aligning with where formal AI security standards are heading, before they harden into certification schemes and contract clauses.
The intended readers
Who should follow it
The Code speaks to everyone with a hand on an AI system, and its provisions divide naturally by role.
Developers
Organisations building AI systems or models, whether as a product or for internal use. The Code asks them to design for security from the outset: threat modelling the AI-specific attack surface, securing training data and pipelines, and documenting what the system is and is not built to withstand.
Deployers
Organisations that buy or integrate AI built by someone else, which in practice is most UK businesses. Their share of the Code centres on due diligence: understanding what they are adopting, configuring it securely and knowing which security responsibilities the vendor has not taken off their plate.
Operators
Whoever runs AI systems in production day to day. For them the Code is about the unglamorous middle years: monitoring behaviour, managing updates and model changes, responding when something goes wrong, and retiring systems without leaving data or access behind.
The substance
What the principles cover, stage by stage
The Code's principles track the life of an AI system from the drawing board to the skip. That lifecycle framing is its most useful feature: it turns AI security from an abstract worry into a checklist of stages your organisation already recognises.
Secure design
Security considered before a line of the system exists: understanding the threats AI introduces, including attacks that target the model itself, and making design choices that limit them.
Secure development
Protecting the assets that make AI work while it is being built: training data, models, pipelines and the supply chain of components and third-party models they depend on.
Secure deployment
Releasing responsibly: hardened infrastructure, controlled access to the system and its APIs, and clear communication to users about capabilities, limitations and safe use.
Secure maintenance
Keeping the system trustworthy in operation: monitoring inputs and behaviour for signs of attack or drift, applying updates, and treating model changes with the care given to any other production change.
Secure end of life
Decommissioning deliberately: disposing of models and the data they carry properly, revoking access, and making sure a retired system does not linger as an unwatched way in.
Voluntary, with an asterisk
Why a voluntary code still matters
Nobody will fine you for ignoring the Code. Three forces make it consequential anyway. First, procurement: security questionnaires and supplier assessments increasingly ask how AI is secured, and the Code gives buyers a shared vocabulary for the question and your answer. Second, assurance: when a client, insurer or auditor asks whether your AI estate is defensible, alignment with published government guidance is evidence in a way that a home-grown policy is not.
Third, direction of travel. The Code is the UK's opening position in a standards process designed to go international. Organisations that align early get to treat the eventual standard as confirmation of work already done, rather than a remediation project with a deadline.
The other regime
How it relates to the EU AI Act
The two are easy to conflate and very different. The EU AI Act is binding product regulation: risk categories, conformity assessments and fines, applying to UK firms only where their AI reaches the EU. The UK Code is lighter and narrower by design: voluntary, security-focused and applicable to any organisation that chooses to adopt it, wherever its customers are.
They complement each other in practice. The Act tells an in-scope firm what must be true of its high-risk systems; the Code describes much of the security engineering that makes it true. If you are unsure whether the EU regime touches you at all, start with our guide to the EU AI Act for UK companies.
From reading to readiness
The Code of Practice readiness check
As part of the AI Readiness Assessment (£8,500 to £16,700 by scope) we map your AI estate against the Code's provisions: every system you build, buy or run, assessed stage by stage against what the Code expects at that point in its life. You get a gap report in plain English, a prioritised remediation roadmap, and the evidence trail to show clients and auditors that your alignment is checked rather than claimed.
The readiness check slots into our wider AI governance framework if you want the full operating model around it, and the price is published alongside everything else on our pricing page.
Quick answers
Code of Practice questions, answered
Is the AI Cyber Security Code of Practice mandatory?
No, it is voluntary. There is no enforcement body and no penalty for ignoring it. But it is the clearest statement yet of what the UK government considers baseline security for AI systems, it is intended to shape a future international standard, and it is already a natural reference point for procurement and assurance questions. Voluntary today is often contractual tomorrow.
Who does the Code of Practice apply to?
Anyone in the lifecycle of an AI system: the developers who build AI, the deployers who integrate it into their business, and the operators who run it in production. If your organisation uses AI in any serious way, at least some of its provisions describe work you should be doing.
How does it relate to the EU AI Act?
They are different instruments doing different jobs. The EU AI Act is binding product regulation with fines, organised around risk categories. The UK Code is voluntary guidance focused specifically on cyber security across the AI lifecycle. A UK firm selling into the EU may well need both: the Act for legal compliance, the Code for the security substance behind it.
Ahead of the standard
Check your AI estate against the Code
A free 45 minute scoping call establishes what AI you actually run and whether a readiness check makes sense, before you spend a penny.