Ensure AI systems are safe, secure and robust throughout their lifecycle
Under UK AI regulation framework, Principle 1, Part 3
What does it require?
Regulators are asked to ensure AI systems function in a robust, secure and safe way, with risks continually identified, assessed and managed. In practice this is enforced through existing safety, security and data-protection law rather than a new duty.
Practical action
Run lifecycle risk assessments and keep security testing evidence that you can show a regulator.
Who does it apply to?
Non-binding expectation for all AI developers and deployers in regulated activities.
- Sectors
- Cross-sector / all sectors
Evidence examples
- AI risk assessment (report)
Framework mappings
Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| NIST AI RMF 1.0 | MEASURE 2.5–2.7 | Original editorial mapping. | medium |
| ISO/IEC 42001:2023 | Clause 6.1 and Annex A risk controls | Original editorial mapping. | medium |
Similar obligations in other instruments
- Apply minimum risk-management practices to high-impact AI — OMB M-25-21, United States
- Establish a risk management system for high-risk AI — EU AI Act, European Union
- Deployers must implement a risk management policy and programme — Colorado AI Act, Colorado (United States)
- Prioritise, respond to and monitor AI risks (Manage) — NIST AI RMF, United States (voluntary)
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.