ConceptGuidance
Secure by design and secure by default
Is this legally binding?
Guidance. Voluntary guidance. Best practice, not obligation, until a contract or a regulator cites it.
Foundational principle: AI should be secure by design and secure by default, as with all software systems, so system owners manage security risks upstream. Security must be considered holistically at system level.
From the source
“as a key principle, AI should be secure by design and secure by default, as with all software systems”
Guidelines, Section 1 Introduction
Verified against the official source on 2026-08-17. GAGE is not affiliated with or endorsed by any agency named here, and nothing on this page is legal advice. How this is built and checked.