Broker Check

Requirements for an AI Security Policy

February 12, 2024

Tristan Roth, a Certified Information Security Manager, posted on LinkedIn that as soon as a company starts using artificial intelligence, they need to write an AI security policy. Here are his recommended requirements:

  1. The purpose of AI regulation.
  2. Scope - what AI tools are being used, e.g. ChatGPT.
  3. The risks the policy is designed to mitigate.
  4. How employees should access AI tools.
  5. Who is allowed to access AI tools and for what purpose.
  6. Security authentication mechanisms.
  7. Guidelines for protection of sensitive information.
  8. Authorized and prohibited uses, with examples.
  9. Data retention control and mitigation.
  10. Monitoring tools.
  11. Training and awareness requirements.