Artificial Intelligence is rapidly transforming cyber security.
Whether it’s accelerating vulnerability research, identifying attack patterns, improving detection capabilities or assisting with report generation, AI is becoming an increasingly valuable tool for security professionals. It’s also changing the way cyber criminals operate, enabling more convincing phishing campaigns, automated reconnaissance and increasingly sophisticated attacks.
The reality is simple: AI isn’t going away.
The conversation has moved beyond whether organisations should adopt AI. Instead, we need to ask a much more important question:
How can AI be used responsibly, securely and ethically?
That’s why Securebytes is proud to be a Founding Signatory of the CREST AI Charter, joining organisations across the global cyber security community in committing to a common set of principles for the responsible use of Artificial Intelligence.
For us, signing the Charter isn’t simply about embracing new technology, it’s about ensuring innovation never comes at the expense of trust.
Why an AI Charter is Needed
Cyber security has always been built on trust. Clients trust security consultants with sensitive information, critical infrastructure and business-critical decisions. Introducing AI into that relationship creates enormous opportunities, but it also introduces new responsibilities.
Organisations need confidence that:
- their data remains secure
- AI isn’t making decisions without appropriate oversight
- outputs are accurate and validated
- confidential information isn’t being used to train public models
- third-party AI providers are properly assessed
- there are governance processes behind every AI-enabled activity.
Without clear principles, organisations risk inconsistent practices, reduced transparency and a loss of confidence in how AI is being used.
The CREST AI Charter provides a framework to help the cyber security industry adopt AI responsibly while maintaining the professional standards clients rightly expect.
The Principles of the CREST AI Charter
Accountability and Governance
Every use of AI should have a clearly defined purpose.
Before AI is introduced into any process, organisations should understand how it may affect service delivery, client outcomes, decision making, operational risk and data handling.
Good governance means AI isn’t simply adopted because it’s available, it is assessed, monitored and controlled throughout its lifecycle.
At Securebytes, we believe responsibility always remains with people. AI can assist our consultants, but accountability for the quality of our work always rests with us.
Transparency of Use
Clients deserve to know when AI is being used.
Transparency builds confidence by ensuring organisations understand where AI contributes to the services they receive, how it affects their data and what limitations may exist.
Being transparent also means explaining where AI adds value and where human expertise continues to play the leading role.
AI should never be treated as a mysterious “black box.”
Documentation and Auditability
One of the greatest strengths of professional cyber security is evidence.
Whether delivering a penetration test, Cyber Essentials assessment or incident response engagement, decisions should be supported by documentation.
The same principle applies to AI.
Organisations should maintain records showing how AI was used, how outputs were validated, what quality assurance was performed and how conclusions were reached.
This creates confidence, supports internal governance and enables external assurance where required.
Boundaries and Control
AI should operate within clearly defined limits.
Competent professionals must retain oversight of AI-assisted activities, reviewing outputs, challenging conclusions and intervening whenever necessary.
AI should never operate outside agreed scope or organisational controls.
Human judgement remains essential.
AI may be incredibly capable, but it lacks business context, professional experience and the ability to understand every nuance of a client’s environment.
Data Handling, Sovereignty and Client Control
Data is one of an organisation’s most valuable assets.
When AI is introduced into service delivery, organisations must understand exactly how client information is processed, stored and protected.
Questions such as:
- Is data used to train AI models?
- Where is information stored?
- Does data leave the agreed jurisdiction?
- Who has access?
- What contractual protections exist?
These are no longer optional questions, they’re essential considerations.
Clients should always understand how their information is handled and retain confidence that contractual, legal and regulatory obligations are being met.
Security and Confidentiality
Using AI securely is just as important as using AI effectively.
Prompts, outputs, client information and AI-generated artefacts all require appropriate protection.
Security controls, access management, encryption and organisational governance remain fundamental regardless of whether work is performed by people or supported by AI.
AI should strengthen security, not introduce new vulnerabilities.
Secure Development of AI Tooling
Many organisations are now building their own AI-enabled tools or integrating AI into existing platforms.
These systems should be developed with the same secure-by-design principles expected of any other software.
Security testing, ongoing maintenance, lifecycle management and governance should all form part of AI development.
Innovation should never come at the expense of security.
Supply Chain Assurance
AI rarely exists in isolation.
Many organisations rely on third-party AI providers, cloud platforms or foundation models to deliver AI capabilities.
These dependencies introduce supply chain risk.
Understanding who provides the technology, how they protect data, where processing occurs and how resilient their services are is critical.
Clients deserve transparency where third-party AI materially contributes to the services they receive.
Resilience and Business Continuity
Like any technology, AI systems can fail.
Services may become unavailable.
Models may change.
Providers may experience outages.
Responsible organisations should understand these risks and maintain contingency plans where appropriate.
Cyber security services should remain resilient even if AI-enabled capabilities become unavailable.
Business continuity planning remains just as important in an AI-enabled world as it has always been.
What This Means for Securebytes
Artificial Intelligence already has a valuable role to play within cyber security.
Used appropriately, it enables us to automate repetitive tasks, improve efficiency, accelerate research and enhance the consistency of our documentation.
However, AI does not replace the experience of a qualified penetration tester.
It does not replace professional judgement.
It does not replace critical thinking.
And it certainly does not replace accountability.
Every finding we report, every recommendation we make and every assessment we deliver remains the responsibility of our consultants.
AI assists our work, it does not define it.
Looking Ahead
The future of cyber security will undoubtedly involve Artificial Intelligence.
Attackers will continue adopting it.
Defenders will continue improving it.
Regulators will increasingly expect organisations to demonstrate responsible governance around its use.
In time, we expect responsible AI governance to become as fundamental to cyber security as information security management, secure software development and risk management are today.
Those organisations that establish robust AI governance now will be best positioned to earn and maintain client trust in the years ahead.
A Commitment to Responsible Innovation
At Securebytes, we believe innovation and responsibility must go hand in hand.
Technology should empower people, not replace them.
Artificial Intelligence has enormous potential to improve cyber security, but only when it is implemented thoughtfully, governed appropriately and used transparently.
We’re proud to stand alongside the other Founding Signatories of the CREST AI Charter in helping shape a future where AI strengthens cyber security while maintaining the professionalism, trust and accountability that our industry depends upon.
Because AI isn’t the future anymore.
It’s the present.
The organisations that succeed won’t simply be those that use AI.
They’ll be the ones that use it responsibly.

