18 countries, including Japan and the US, jointly announce AI safety development guidelines



On November 27, 2023, 18 countries, including the United States and Japan, jointly announced guidelines for AI development, called ' Guidelines for Secure AI System Development .' The guidelines call for protecting user privacy and properly managing documents during the development, operation, and maintenance of AI.

Guidelines for secure AI system development - NCSC.GOV.UK

https://www.ncsc.gov.uk/collection/guidelines-secure-ai-system-development



Guidelines for secure AI system development - Guidelines-for-secure-AI-system-development.pdf
(PDF file)

https://www.ncsc.gov.uk/files/Guidelines-for-secure-AI-system-development.pdf

Secure AI System Development Guidelines
(PDF file) https://www.nisc.go.jp/pdf/press/press_Guidelines_for_Secure_AI_System_Development.pdf

The following countries and organizations support the newly created guidelines:
Country name Institution Name
America Cybersecurity and Infrastructure Security Agency (CISA)
National Security Agency (NSA)
Federal Bureau of Investigation (FBI)
England National Cyber Security Agency (NCSC)
Japan National Center of Incident Readiness and Strategy for Cybersecurity (NISC)
Australia Australian Cyber Security Centre (ACSC)
Canada Canadian Centre for Cyber Security (CCCS)
Chile Chilean Government
Czech Republic National Cyber and Information Security Agency (NUKIB)
Estonia Information Systems Agency (RIA)
National Cyber Security Centre (NCSC-EE)
France French Cybersecurity Agency (ANSSI)
Germany German Federal Office for Information Security (BSI)
Israel Israel National Cyber Directorate (INCD)
Italy Italian National Cybersecurity Agency (ACN)
new zealand National Cyber Security Center
Nigeria National Information Technology Development Agency (NITDA)
Norway National Cyber Security Centre (NCSC-NO)
Poland NASK National Laboratory
South Korea National Intelligence Service of the Republic of Korea (NIS)
Singapore Cyber Security Agency of Singapore (CSA)


The guidelines are divided into four sections: 'Secure Design,' 'Secure Development,' 'Secure Deployment,' and 'Secure Operation and Maintenance,' and each section includes suggestions for improving the AI development cycle and protecting the public. The main points of each section are as follows:

・Secure design
Before development even begins, development staff must be made aware of the security risks inherent in AI and how to mitigate them. Security decisions must also be made at the same time as deciding on the AI functions to be developed.

・Safe development
During the development phase, supply chain security, document management, asset protection, and proper management of technical debt are required.



・Safe deployment
Appropriate protection of the infrastructure used to support AI systems, including access control rights for APIs, models, and data, is essential. It's also important for developers to prepare response and remediation plans in advance in case a security incident occurs and issues surface. Furthermore, AI model functions and trained data must be continuously protected from attackers and should only be released after passing a thorough security assessment.

・Safe operation and maintenance
When monitoring AI behavior, signs of misuse must be properly monitored and logged to meet privacy and data protection requirements, and updates must be automatically updated on a regular basis to prevent the use of outdated or vulnerable versions.

Lindy Cameron, CEO of the UK's National Cyber Security Agency, said: 'These guidelines are a key part of building a truly global common understanding of the cyber risks surrounding AI, ensuring that security is not just a developmental component, but a core part of the whole of AI.'



While the guidelines are not legally binding, CISA Director Jen Easterly said, 'It is significant that so many countries have signed on to these guidelines, which prioritize the security of AI systems. These are the first guidelines where countries have agreed that AI development and deployment should not just be about breakthrough features, speed to market, or cost reduction.'

The Japanese translation of the 'Guidelines for Developing Secure AI Systems' can be found at the link below.

Guidelines for developing secure AI systems
(PDF file)

https://www.nisc.go.jp/pdf/policy/kokusai/Provisional_Translation_JP_Guidelines_for_Secure_AI_System_Development.pdf

in AI,   Software, Posted by darkhorse_log