Security works best built in from the start, not bolted on before launch.
Design
- Threat model the system.
- Decide on data sensitivity, model choice and required permissions.
- Apply least privilege to tools and data access.
Data
- Verify provenance and licences.
- Scrub secrets and unnecessary personal data.
- Control and log changes to datasets.
Development
- Keep prompts, configurations and code in version control.
- Review code that handles model output.
- Vet third-party models, libraries and tools.
Testing
- Security evaluations: injection, leakage, jailbreaks, unsafe output handling.
- Red teaming for significant systems.
- Regression suites of known attacks.
Deployment
- Authentication, rate limits and quotas.
- Secrets management.
- Staged rollouts with monitoring.
Operations
- Monitoring and alerting.
- Incident response procedures.
- Regular review as models, data and tools change.
Guidance
Government security agencies and industry groups have published secure AI development guidelines worth consulting.