In order to ensure that AI systems are robust and safe, parliaments should adopt a comprehensive, dynamic risk management approach that adapts to the ever-changing environment in which these systems operate. The components of this approach are detailed below:
Comprehensive testing: Identify and mitigate cyber threats specifically targeting AI systems, while not neglecting other potential vulnerabilities.
Security practices: Tailor security practices to address the unique challenges posed by AI systems and the threats they face, including through close and rapid communication between data teams and information security experts. When developing AI systems, cybersecurity should be a primary consideration, integrated from the outset, rather than added as an afterthought.
Training: Invest in continuous training for developers and information security staff. These staff should be well-versed in techniques to prevent cyberattacks on AI systems and equipped with disaster recovery strategies specific to these technologies.
Internal collaboration: Ensure that internal business units responsible for AI systems work closely with IT departments to establish clear parameters for monitoring system behaviour and defining thresholds for alerts regarding suspicious activity.
External partnerships: Forge partnerships with other public institutions. These alliances facilitate swift and effective communication about emerging threats and new attack categories. They also provide a platform for sharing experiences – both successes and failures – in implementing various security techniques and technologies.
By adopting this holistic approach, parliaments can create a resilient framework for AI systems that can withstand threats, adapt to changes, and continue to serve their intended purpose effectively and safely.