Security & Resilience
GPAI Cybersecurity Protection
What this control does
Maintain adequate cybersecurity for systemic-risk GPAI models and their physical infrastructure.
How to implement
For a provider of GPAI with systemic risk, assess cybersecurity across the model and its supporting physical infrastructure. Assign owners for access, model protection, infrastructure security, monitoring and incident response. Choose safeguards proportionate to the identified threats and dependencies. Test important protections, track weaknesses and verify corrections after changes or incidents. Coordinate with the systemic-risk and incident processes rather than treating infrastructure certification alone as sufficient model protection.
Suggested timing and triggers
Throughout the model lifecycle; after relevant model, infrastructure, dependency or threat changes; periodic security assessment.
Evidence examples
Model and infrastructure threat assessment Access and protection configurations Security testing and monitoring evidence Supplier or dependency assurance where relevant Remediation, retest and incident records
How to check this control
Trace a significant threat to its control and test evidence. Sample privileged access and one infrastructure or model change, checking that weaknesses were addressed and the relevant owners were informed.