Seventy-three signatories, one shared promise
More than 70 cybersecurity organizations have signed onto a new charter that commits them to responsible and transparent use of artificial intelligence in their security operations. The AI security charter, launched July 9 by the cyber industry body CREST, aims to bring order to a fast-moving field where AI tools are increasingly common — and increasingly opaque.
The charter is built around nine principles first unveiled in March. They cover everything from basic accountability to long-term business continuity, and signatories are expected to follow through on each one.
The nine principles powering the AI Charter
CREST distilled its framework into a clear set of commitments. Here is what the signatories have agreed to:
- Accountability and governance — Firms must define the scope and purpose of every AI-enabled activity and assess how it affects service delivery, client outcomes, data handling and operational risk.
- Transparency of use — Clients must be told when AI is part of the tool or methodology they are buying, along with the benefits, limitations and risks involved.
- Documentation and auditability — Traceable records of AI use must be kept, backed by validation and quality assurance processes that support compliance audits.
- Boundaries and control — Qualified personnel retain final oversight, with the power to intervene, review outputs and challenge AI-driven decisions.
- Data handling, sovereignty and client control — Firms must disclose whether client data will be used to train models or transferred across borders, and ensure all data use aligns with legal and contractual terms.
- Security and confidentiality — Client prompts, outputs and AI-generated assets must be protected through robust security controls.
- Secure development of AI tooling — Secure practices must apply across the entire lifecycle of AI tools, from design to deployment.
- Supply chain assurance — Third-party AI dependencies must be identified and managed for risk.
- Resilience and business continuity — Firms must plan for AI failures, establish fallback arrangements and be transparent with clients about how disruptions could affect service levels.
The principles are not just theoretical. They set concrete expectations for how AI should be governed inside a cybersecurity firm. And they apply regardless of whether the AI in question is a large language model, a threat detection algorithm or an automated response system.
Why this matters now
AI is already embedded in daily cybersecurity work. CREST recently found that 69% of cybersecurity providers now use AI in daily service delivery, and 76% say that usage has grown over the past year. That rapid adoption creates a gap: tools are evolving faster than the rules around them.
The 73 founding signatories represent about 10% of CREST’s membership, spanning Europe, North America, the Middle East and Asia-Pacific. They include firms working in penetration testing, vulnerability assessment, incident response, security operations and threat intelligence.
Nick Benson, CEO of CREST, called the charter “just the start.” Speaking to Infosecurity, he said he expects a “snowball effect” as more organizations, governments and providers adopt the same principles.
CREST frames its approach as self-regulation — an attempt to make formal regulation “less necessary and the compliance burden lighter.” But Benson also acknowledged that principles alone are not enough. “It is absolutely critical that we move rapidly beyond the principles to establish thorough standards that can be independently assessed against,” he said.
How the principles were built
CREST did not write the charter in isolation. The organization reviewed existing frameworks on AI use in cybersecurity, gathered feedback from members and industry leaders during CRESTCon Leaders Days and other events, and validated the final principles through its technical committee.
A key question guided the work, a CREST spokesperson told Infosecurity: “What sets AI-driven cyber services apart from traditional ones?” The answer shaped the nine principles, which focus on the unique risks and responsibilities that come with AI-powered tools.
What comes next for AI governance in cybersecurity
The charter is voluntary today. But CREST hopes it becomes a baseline that governments and regulators recognize and point to. Benson said the industry body would “welcome regulators supporting and signposting these principles.” He added that aligning national standards with CREST’s framework “will promote harmonization, cross-border interoperability and minimize frictional costs for both buyers and vendors.”
For cybersecurity buyers, the AI security charter offers a way to vet vendors. If a provider is a signatory, clients know the firm has committed to transparency, data sovereignty and human oversight. That is a meaningful signal in a market where AI hype often outpaces actual accountability.
The charter also ties into broader efforts to standardize responsible AI use across industries. While cybersecurity has its own specific needs — around threat data, client confidentiality and operational speed — the principles here echo themes seen in other sectors: transparency, auditability and human control.
CREST’s move arrives alongside other industry-led initiatives. The UK government recently launched its own Cyber Resilience Pledge, which also relies on voluntary commitments from signatories. Taken together, these efforts suggest a growing consensus: self-regulation may be imperfect, but it is better than waiting for a crisis to force action.
Benson put it plainly: “We expect this to have a snowball effect.” Whether that snowball becomes an avalanche will depend on how many firms sign on — and how seriously they take the principles they have endorsed.