Join our Newsletter — 33% off our NHI Course
Home› Glossary› Governance, Ownership & Risk› AI Cyber Security Code of Practice
Governance, Ownership & Risk

AI Cyber Security Code of Practice

← Back to Glossary
By NHI Mgmt Group Updated September 24, 2026 Domain: Governance, Ownership & Risk

A set of recommended security controls for building, deploying, and operating AI systems safely. It typically covers governance, access control, data protection, model integrity, logging, incident response, and supply chain risk. In practice, it translates AI risk into operational requirements that security, engineering, and compliance teams can apply consistently.

What the code of practice is for

An AI cyber security code of practice is a control-oriented reference point, not a product or a law. It turns broad AI risk into practical expectations for how systems should be designed, deployed, monitored, and governed across the AI lifecycle.

Its value is that it gives security, engineering, and compliance teams a common operational language. That usually makes it easier to decide which safeguards are mandatory, which are risk-based, and which need to be verified before a system goes live.

What it usually covers

Most codes of practice group requirements around a few repeatable control areas: governance and accountability, access control, data protection, model and prompt integrity, logging, incident response, and supply-chain assurance. Those topics matter because AI systems can fail through the same basic control weaknesses that affect other software, but often at greater speed and scale.

In practice, this means the code should help answer questions such as who can change the system, what data it may use, how outputs are monitored, and what evidence exists that controls are actually working. A useful code is specific enough to be applied, but flexible enough to fit different AI architectures and deployment patterns.

How it shapes AI security controls

The strongest codes of practice do more than repeat general security advice. They connect AI-specific failure modes, such as prompt manipulation, model tampering, unsafe tool use, training-data contamination, and insecure integrations, to concrete security requirements.

That makes them useful as a bridge between policy and implementation. Teams can map the code to NIST AI Risk Management Framework principles for governance, to NIST Cybersecurity Framework 2.0 for cross-cutting security outcomes, and to NIST Privacy Framework where AI processing creates privacy risk. It can also align with NIST SP 800-53 Rev 5 Security and Privacy Controls when the organisation needs a formal control catalogue.

Because AI systems often expose APIs, external tools, and automated workflows, the code should also reinforce least privilege, secure defaults, and evidence-driven validation rather than trusting model behaviour alone.

Why it matters in real deployments

A code of practice matters because AI risk is rarely confined to the model itself. Exposure often appears in surrounding systems, such as data pipelines, secrets handling, third-party services, logging, and access paths that were added for speed rather than control.

For that reason, practitioners often use a code of practice to separate baseline controls from higher-risk exceptions. It becomes the reference point for deciding when an AI use case needs stronger review, stronger logging, tighter data boundaries, or more explicit approval before production rollout.

Risk and Threat Considerations

AI security codes fail when they stay too generic or are treated as documentation instead of enforceable control intent. The main risk is that teams assume AI-specific safeguards exist because a policy exists, while the actual system still contains weak data handling, excessive access, poor logging, or unsafe third-party dependencies.

Failure mechanism: Attackers and internal users can exploit the gap between written guidance and real implementation, especially where models, tools, secrets, and data stores are loosely connected.

Impact: That gap can lead to prompt injection, data leakage, model tampering, unauthorised actions, and weak incident containment, particularly when the AI system is integrated into high-trust business workflows.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST AI RMF, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST AI RMFGovernAI codes of practice operationalise AI risk governance and accountability.
Recommendation — Use governance outcomes to turn the code into owned AI risk controls.
NIST CSF 2.0GV.RM-01 — Risk Management StrategyThe code translates AI risk into a repeatable security risk strategy.
PR.DS-01 — Data ManagementThe code covers data handling, protection, and AI training/usage boundaries.
PR.AA-05 — Least Privilege for Access Authorizations and EntitlementsAccess control is central to safe AI system operation and tool use.
Recommendation — Align AI control requirements to enterprise risk management decisions. Define data handling rules for AI inputs, outputs, and training sources. Restrict AI system access, entitlements, and tool permissions to least privilege.
CIS Controls v8CIS-6 — Access Control ManagementAI codes commonly require disciplined access control across systems and data.
Recommendation — Apply access control management to AI platforms, data, and supporting services.

Practitioner Guidance

Governance implication: Treat the code as a minimum security baseline that must be translated into reviewable engineering and operational controls. If a proposed AI system cannot show how it meets the code, the gap should be resolved before deployment, not after the first incident.

What to watch for: The warning sign is a code that reads well but cannot be traced to owners, test evidence, logging coverage, approval criteria, or rollback procedures. In practice, the best codes are the ones teams can actually inspect, test, and enforce.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 24, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org