Join our Newsletter — 33% off our NHI Course
Home Glossary Cyber Security Duty Of Care
Cyber Security

Duty Of Care

← Back to Glossary
By NHI Mgmt Group Updated August 20, 2026 Domain: Cyber Security

A duty of care is a legal obligation to take reasonable steps to prevent foreseeable harm. In online safety contexts, it requires platforms to assess risks, apply controls, keep records, and show that safety measures are proportionate to the service and the users affected.

Expanded Definition

Duty of care is a legal and governance concept, but in cybersecurity and online safety it functions as an operational expectation: an organisation must identify foreseeable harm, assess how likely it is, and take reasonable steps to reduce that risk. It is broader than a single technical control and narrower than a general ethical principle, because it is judged against the service, the users, and the context in which the harm could occur.

In practice, duty of care often overlaps with risk management, incident readiness, documentation, and control selection. The strongest implementations show a clear line from identified hazard to mitigation, monitoring, and review. That is why frameworks such as the NIST Cybersecurity Framework 2.0 are useful: they help teams translate a general obligation into governance, protection, detection, response, and recovery activities.

Definitions vary across jurisdictions and sectors, and no single standard governs this term yet. The most common misapplication is treating duty of care as a one-time legal checkbox, which occurs when teams document a policy but do not test whether controls are proportionate to the actual harm profile.

Examples and Use Cases

Implementing duty of care rigorously often introduces extra review, documentation, and escalation overhead, requiring organisations to weigh speed of release against defensible safety decisions.

  • A social platform maps harmful content scenarios, then records why its moderation thresholds and escalation paths are proportionate to user risk.
  • A SaaS provider assesses account takeover, data exposure, and abuse paths, then aligns monitoring and response playbooks to the most foreseeable harms.
  • A marketplace keeps audit records showing how identity checks, fraud controls, and dispute handling were selected to reduce predictable customer harm.
  • An AI service operator documents known failure modes, human oversight points, and escalation criteria to show reasonable steps were taken before deployment.
  • A cloud security team links a control set to business impact analysis and incident evidence, often using the NIST Cybersecurity Framework 2.0 as the structure for that mapping.

These examples show that duty of care is not just about having controls, but about being able to explain why those controls were chosen, how they were validated, and what risk they were intended to reduce.

Why It Matters for Security Teams

For security teams, duty of care matters because it shapes how risk decisions are defended after an incident, complaint, or regulatory review. If the organisation cannot show that it considered foreseeable harm, selected proportionate safeguards, and maintained evidence, even strong technical measures may look arbitrary or incomplete.

This concept is especially important where identity, access, and agentic AI intersect. Poor authentication design, weak privileged access controls, or uncontrolled AI agents can all create foreseeable harm, and duty of care forces teams to treat those exposures as governance issues, not just technical defects. When the service handles personal data or trust-sensitive workflows, the expectations around documentation and proportionality become even more visible.

Security leaders typically encounter the practical weight of duty of care only after a breach, abuse event, or harm claim, at which point evidence of reasonable prevention and response becomes operationally unavoidable to produce.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST AI RMF and NIST SP 800-63 set the technical controls, while EU AI Act and NIS2 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OC-01Outlines organisational context and risk priorities relevant to duty of care.
NIST AI RMFGOVERNGovernance functions support accountability, documentation, and risk ownership for AI-related duty of care.
NIST SP 800-63IAL2Identity assurance levels help define reasonable steps when identity proofing is part of harm prevention.
EU AI ActRequires risk management and technical documentation for certain AI uses tied to foreseeable harm.
NIS2Expects appropriate and proportionate cybersecurity risk-management measures for covered entities.

Maintain risk files and technical records showing controls are proportionate and continuously reviewed.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 20, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org