Assess an AI system against the UK cyber-security code
Review one planned or live AI system against the government code, retain the evidence tested and assign every open security action.
Tool available. Run the complete browser-local workflow and inspect the result. Paid export is not active. Entries and files stay in this browser. Sources reviewed 7 August 2026.
Built from fictional sample information using the same exporter as the tool.
UK AI cyber-security self-assessment sampleWhat’s included
Orient the reviewer
Explain the supplied files, current status, recommended review and limits of the voluntary-code assessment.
- Start Here PDF
Review and improve the controls
Use the report, control register and editable improvement plan to test evidence and close actions.
- Self-assessment report PDF
- Control and action register XLSX
- Improvement plan DOCX
Retain the evidence trail
Keep the complete structured record and its official sources, assumptions and decision limits.
- Structured self-assessment JSON
- Sources and assumptions record
View every output and format
- Start Here PDF
- Self-assessment report PDF
- Control and action register XLSX
- Improvement plan DOCX
- Structured self-assessment JSON
- Sources and assumptions record
Who this tool is for
Security, engineering, operations, procurement and AI governance teams reviewing a planned, live or materially changed AI system. Create an owned security evidence record across the AI lifecycle without presenting a voluntary-code assessment as certification.
Supported use
- One planned, live or materially changed AI system in a UK governance route
- Developer, system operator, data custodian, provider or combined stakeholder responsibilities
- Evidence checks across secure design, assets, infrastructure, supply chain, data, models, prompts, testing, operation and disposal
Have ready
- The system, deployment route, stakeholder role and lifecycle phase
- Criticality, data sensitivity, hosting architecture, suppliers and external components
- The security owner and incident escalation route
- Exact implementation or test evidence, control owner and review date for every principle
Needs separate review
- Certification, penetration testing or independent assurance
- Whether the controls are proportionate to a particular threat model
- Research-only systems with no deployment planned and obligations outside the supported code
How it works
- Set the security scopeRecord the stakeholder role, deployment route, lifecycle phase, criticality and data sensitivity.
- Describe the architectureRecord hosting, models, datasets, external components, suppliers, security ownership and the incident route.
- Review the evidenceCheck every supported lifecycle principle against exact implementation or test evidence.
- Assign improvementsGive every missing or uncertain control an owner and due date, then export the controlled record.
Where does this task apply?
Choose the guidance set this tool should use. The interface and outputs stay in English.
Assess the evidence behind the UK AI cyber-security code.
Review one AI system against the government code’s lifecycle principles, retain the evidence tested and assign every open security action.
The DSIT AI Cyber Security Code of Practice is voluntary. This tool does not certify security or conformity with a standard.
A recorded control does not prove operational effectiveness. Review the underlying evidence and test results.
What this tool checks
The scope stays narrow so the result is clear and reproducible.
- Records the stakeholder role, deployment route, lifecycle phase, criticality, data sensitivity, architecture and suppliers.
- Checks evidence across secure design, assets, infrastructure, supply chain, data, models, prompts, testing, operation and disposal.
- Keeps the voluntary code distinct from certification and treats research-only systems as outside the supported deployment route.
From official material to a working record
Official material sets the basis
The UK government code and implementation guide describe voluntary cyber-security principles for AI stakeholders.
The tool prepares the operational record
The self-assessment creates a repeatable evidence record with exact control references, test dates, owners and open improvements.
Official sources stay visible
Each supported check shows its jurisdiction, source title, source version and review date beside the result. Unsupported cases are rejected rather than estimated.
View this product's official sourcesQuestions before you use the tool
Scope, files, evidence and browser-local handling.
Does this certify compliance with the code?
No. The code is voluntary and the tool does not certify security or control effectiveness.
Can I use it for a research-only system?
The supported route covers systems planned for deployment, live systems and material changes. A research-only answer is retained as outside that route.
What counts as implementation evidence?
Use an exact design, configuration, access review, test, monitoring, exercise, incident or disposal record a reviewer can inspect.
Where is the security information processed?
The entered architecture, control evidence and generated files remain in this browser on this device.
Create the security evidence record
Set the system scope, review every lifecycle control and assign each open improvement.