RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026Start here · 100 retrospective records ↗
AI Use Field Guide

Start here / Privacy & safety

Privacy & safety / From the archive · 27 November 2023 event · prepared 16 September 2026

Security agencies from more than twenty nations agreed on one guide

A joint CISA-NCSC guidance document sets secure-by-design practices for building AI systems, agreed globally for the first time, the agencies state.

Visual published with the cited source for this record: Security agencies from more than twenty nations agreed on one guide
Visual published with the cited source, shown for identification of the record. Credit: ncsc.gov.uk · source page ↗ Rights: owner-review-pending.

Start here

Most people will never build an AI system, but many now work at, buy from, or trust organisations that do. On 27 November 2023 the US Cybersecurity and Infrastructure Security Agency and the UK's National Cyber Security Centre jointly published Guidelines for Secure AI System Development, described as the first agreed security guidance of its kind at global scale. For a reader deciding whether to trust a vendor's AI product, this document is a useful yardstick: it names what a security-conscious provider should already be doing.

What the documents say

The guidelines are organised around four life-cycle stages: secure design, development, deployment, and operation and maintenance. The document aims to help providers 'build AI systems that function as intended, are available when needed, and work without revealing sensitive data to unauthorised parties,' following a 'secure by default' approach aligned with NIST and the NCSC's own software guidance. A companion CISA press release, dated 26 November 2023, states the guidelines were 'formulated in cooperation with 21 other agencies and ministries from across the world,' including every G7 member, quoting then-Secretary of Homeland Security Alejandro Mayorkas calling cybersecurity 'key to building AI systems that are safe, secure, and trustworthy.' Neither document is a technical standard with pass or fail tests; both describe recommended practices for organisations to weigh, not requirements enforced by a regulator.

Check this

A reader without a technical background can use this as a checklist for a vendor conversation. The guidelines name specific practices: threat modelling during design, supply chain security during development, incident management during deployment, and logging plus update management during operation. Asking a vendor, or a workplace's IT team, whether they follow guidance aligned with these four stages is concrete and answerable, unlike asking whether an AI product is simply 'safe.'

What holds and what fails

The guidelines hold as a description of responsible AI development, endorsed by cyber agencies across many countries rather than one company marketing its own practices. They do not hold as a guarantee: adoption is voluntary, the document is guidance rather than law, and neither agency claims to have verified which vendors follow it. Treat a vendor's claim of following 'secure by design' principles as something to check, for example by asking what incident response process exists, not as a fact established by the guidelines' publication alone.

  • Ask a vendor whether their AI development practices are aligned with published secure-by-design guidance.
  • Look for a named incident response or vulnerability disclosure process before trusting a new AI tool.
  • Treat 'secure by design' as a specific set of practices to ask about, not a marketing phrase to accept.

International agreement among cyber agencies is itself informative: it signals AI-specific security risk is now a mainstream discipline, even though the guidelines stop short of making any single practice mandatory.

Sources & reading trail

Guidelines for secure AI system development ↗

The joint guidance document itself: four life-cycle stages, secure-by-default approach, and its aims.

Source published: 27 November 2023 · Retrieved: 16 September 2026

DHS CISA and UK NCSC Release Joint Guidelines for Secure AI System Development ↗

Announces the guidelines, names 21 co-signing agencies including the G7, and quotes DHS and CISA leadership.

Source published: 26 November 2023 · Retrieved: 16 September 2026

Documentation, regulator guidance and studies establish the record; the checks and the boundary are AI Use Field Guide editorial analysis. This retrospective draft does not imply the site published on the event date.