AI Cyber Security Code of Practice Compliance Check
Check whether your business's AI systems meet the UK government's AI Cyber Security Code of Practice, now underpinning the global ETSI TS 104 223 standard.
Why this matters
The UK Department for Science, Innovation and Technology published the AI Cyber Security Code of Practice in January 2025, setting out thirteen principles covering the secure design, development, deployment, maintenance and end-of-life of AI systems. It was developed with the National Cyber Security Centre specifically because general software security guidance doesn’t address AI-specific risks such as data poisoning, prompt injection, model theft, adversarial inputs and unintended behaviour from third-party or fine-tuned models. The Code has since been developed into a global technical standard through the European Telecommunications Standards Institute (published as ETSI TS 104 223), meaning it is rapidly becoming the reference baseline that procurement teams, cyber insurers, and enterprise customers point to when assessing whether a supplier’s AI product or integration is secure.
The Code is voluntary rather than a legal requirement, but that doesn’t make it optional in practice for most UK businesses building, integrating or deploying AI features. It sits alongside the Cyber Security and Resilience Bill’s push to strengthen supply chain security, and businesses selling AI-powered products or services into the public sector, financial services or larger enterprise customers are increasingly being asked to demonstrate alignment with it during procurement and due diligence. Startups and SMEs building on top of third-party large language models, chatbots, or AI-driven decision tools often assume responsibility sits entirely with the model provider — but the Code makes clear that system operators and data custodians integrating AI into their own products carry direct responsibility for secure configuration, access control, monitoring and incident response.
What you'll need
- Whether your business develops, fine-tunes, or integrates AI models or AI features into products or services
- Whether you've reviewed the DSIT/NCSC AI Cyber Security Code of Practice or ETSI TS 104 223
- Whether you have documented security processes covering your AI supply chain
- Whether customers, insurers or procurement teams have asked about your AI security posture
What you'll get
A personalised compliance report covering: a score out of 100, an executive summary, a list of findings ranked by severity, and a prioritised action plan with timeframes.
Use this free tool to check whether your business’s AI systems align with the UK government’s AI Cyber Security Code of Practice — now underpinning the global ETSI TS 104 223 standard — covering secure design, deployment, monitoring and end-of-life. Get a clear action plan in minutes.
General guidance only — not legal advice. Consult a qualified UK solicitor for specific issues.