Over 70 cybersecurity organizations have signed a new charter, vowing responsible use of AI for cybersecurity purposes.
The AI Charter was launched by cyber industry body CREST on July 9 and is based on nine principles that were first outlined in March for AI-related cybersecurity activities:
What Are CREST’s Principles for AI-Enabled Cybersecurity?
The first pledge by the signatories was to accountability, governance and transparency. The principles are intended to direct signatory firms to establish a clear scope of all AI-assisted activities and outline the goals of the use of AI, and to thoroughly evaluate the impact of these activities on service delivery, client outcomes, data handling, and operational risks. Governance and testing controls need to be commensurate with the size of the AI deployment.
Additionally, companies commit to a completely transparent approach, communicating to clients when they are using AI in tools or processes, and outlining the benefits, drawbacks and dangers.
Documentation, auditability, human supervision and data sovereignty are highlighted in the charter to ensure trust and integrity in operation.
Signatories agree to maintain records of their use of AI that are traceable and can be reviewed, as well as validation and quality assurance measures in place, to support compliance audits.
Though AI tools can work at different levels of independence, the charter states that there should always be “qualified personnel” in place to have the “last mile of control,” meaning they retain the power to step in, review outputs, and challenge decisions.
Furthermore, data handling is superbly controlled: companies have to explicitly state whether client data is being used to train models or data is being shared between jurisdictions, and ensure that all data operations are perfectly in line with agreed legal, regulatory and contractual commitments.
Charter pillars one and three centre on securing the technology and the development of long-term operational resilience. AI firms must implement comprehensive security and confidentiality measures to protect client prompts, outputs, and AI-created assets, along with securely developing and integrating their AI tools throughout the entire lifecycle.
This security approach applies to the supply chain as well, and signatories must be able to recognize and address the security risks associated with any third-party requirements for AI.
Lastly, businesses need to be prepared for the worst-case scenarios when it comes to AI systems, making contingency plans and being the most transparent with the client about the impact that system failures might have on the level of service and recovery time they can expect to receive.
Who Are the Over 70 Signatories to the CREST AI Charter?

These principles have been informed by CREST’s members, feedback from industry leaders at the CRESTCon Leaders Days as well as other events, and validated by CREST’s technical committee.
One of the major considerations for the principles chosen was “what constitutes an AI-based cyber service as opposed to a traditional service”, as a CREST spokesperson told Infosecurity.
In support of the announcement, CREST reported that it recently discovered that 69% of cybersecurity service providers are now employing AI in their service delivery, while 76% stated that they have seen increased adoption of AI over the last year.
The 73 founding signatories of the CREST AI Charter include 10% of CREST’s members, spread across European countries, North America, the Middle East, and Asia-Pacific.
These cover companies in a wide range of domains of cybersecurity, such as penetration testing, vulnerability assessment, incident responding, security operations, and threat intelligence.
Why Is There a Critical Need for AI Cybersecurity Standards?
The AI Charter is “just the start”, Nick Benson, CEO of CREST, told Infosecurity. We hope that this will have a domino effect, with organisations, governments and providers following suit in the implementation of these shared principles.
Describing its model as “one of self-regulation, aimed at enabling a functioning, successful market,” CREST hopes the AI Charter can make “regulation less necessary and the compliance burden lighter.”
However, moving quickly from the principles to “establishing standards that can be independently assessed against” is “absolutely critical” that we do, Benson said.
Moreover, he said the industry body will be “welcoming regulators that support and signpost these principles.”
“Harmonisation, cross-border interoperability and reduction of frictional costs for buyers and vendors will be achieved by aligning national standards to the CREST ones,” Benson concluded.
More than 70 cyber companies have signed a new AI Security Charter that addresses risks from artificial intelligence, with answers to frequently asked questions.
FAQs:
1. What is new in the AI Security Charter?
The new AI Security Charter represents a cybersecurity initiative to provide best practices, guidelines, and standards for the development and use of AI systems in a safe manner. It aims at minimizing security threats and enhance security from AI and cyber attacks.
2. Who endorses the AI Security Charter?
Over 70 cybersecurity companies and industry groups contribute to the AI Security Charter, which seeks to foster safer AI development, increased security measures, and responsible use of AI technologies.
3. The AI Security Charter was developed because of 3 things?
The charter was developed in response to the increasing issues in the security of AI, such as data breaches, vulnerabilities in AI systems, cyberattacks, misuse of AI tools, and the necessity for enhanced security measures throughout the AI life cycle.
4. What are the main goals of the AI Security Charter?
These are the major objectives:
Developing AI system security.Enhancing security of AI systems.
Promoting responsible development of AI
Protecting sensitive data
Reducing cybersecurity risks
Promoting collaboration between AI and cybersecurity industries
5. How can AI Security Charter be a tool to enhance cybersecurity?
The charter has the potential to push organisations towards building more robust security regimes, detect and understand risks associated with AI earlier than they would otherwise, enhance threat detection, and develop safer AI application systems that are less susceptible to cyber attacks.