Voluntary guidance AI risk management United Kingdom Guidance

Ensure AI systems are safe, secure and robust throughout their lifecycle

Under UK AI regulation framework, Principle 1, Part 3

Source-linked Open official source

What does it require?

Regulators are asked to ensure AI systems function in a robust, secure and safe way, with risks continually identified, assessed and managed. In practice this is enforced through existing safety, security and data-protection law rather than a new duty.

Practical action

Run lifecycle risk assessments and keep security testing evidence that you can show a regulator.

Who does it apply to?

Non-binding expectation for all AI developers and deployers in regulated activities.

Evidence examples

  • AI risk assessment (report)

Framework mappings

Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.

Framework mappings
FrameworkReferenceNoteConfidence
NIST AI RMF 1.0MEASURE 2.5–2.7Original editorial mapping.medium
ISO/IEC 42001:2023Clause 6.1 and Annex A risk controlsOriginal editorial mapping.medium

Similar obligations in other instruments

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.