DWP AI Security Policy for Government Use

Artificial Intelligence Security Policy (DWP)

United Kingdom

RAI-GB-NA-SECURIT-2026
Effective: August 7, 2026
In Force(In Force)
PolicyGovernance and OversightData Protection and PrivacyRisk Management
Export PDF

The DWP AI Security Policy outlines mandatory and advisory responsibilities for employees, contractors, and suppliers using AI tools for official DWP business, focusing on secure, responsible, and transparent AI use.

Summary

The DWP Artificial Intelligence Security Policy establishes mandatory and advisory responsibilities for end users, including DWP employees, contractors, and suppliers, when utilizing AI tools for official DWP business. Updated on 7 August 2026, the policy aims to ensure the secure and responsible use of AI by outlining acceptable practices, emphasizing data protection, promoting user accountability, verifying the accuracy of AI outputs, and ensuring transparency. It applies to all AI tools, including generative AI, machine learning, and large language models, and details specific requirements for handling sensitive data, personal data, and non-public DWP code. The policy mandates adherence to DWP security standards, data protection principles, and algorithmic transparency requirements, integrating a risk-based approach to align with the organisation's risk appetite.

Full article

Read full text ↗

Overview

The DWP Artificial Intelligence Security Policy, last updated on 7 August 2026, serves as a foundational document within a broader suite of security policies for the Department for Work and Pensions (DWP). Its primary objective is to ensure consistency in the implementation and management of security controls across the DWP and its supplier base, particularly concerning the use of Artificial Intelligence (AI) tools. The policy promotes the measured and controlled adoption of AI, recognising its potential to enhance services through automation, improved data analysis, faster information retrieval, and aid in creativity. It meticulously outlines the responsibilities of end users, encompassing DWP employees and contractors, when engaging with AI tools for official DWP business.

Central to this policy is a risk-based approach, designed to align its statements with the DWP's organisational risk appetite. The policy explicitly aims to guarantee that data protection and information management processes are rigorously followed, users are held accountable for their AI usage, the accuracy of AI-generated information is verified, and transparency is maintained when AI tools are employed. It applies comprehensively to all AI tools, including generative AI, machine learning, and large language models, and extends its requirements to suppliers and their third parties when utilising AI tools for DWP business or in the provision of services to DWP, as detailed in Annex A. This policy complements, rather than replaces, existing legal or regulatory requirements.

Definitions

The policy provides clear definitions for key terms to ensure consistent understanding and application across the DWP and its partners. Artificial Intelligence (AI) is defined as a computer programme that ‘learns’ from data and can perform tasks typically carried out by humans. An AI tool is any computer software that uses artificial intelligence in its processing. The policy distinguishes between Approved AI tools, which are those residing on the DWP infrastructure and sanctioned by the Digital Design Authority (DDA)—the DWP's lead governance board for new digital tools—and Online AI tools, which are accessed via the internet through a web browser. These distinctions are crucial for determining permissible usage and necessary approvals within the DWP ecosystem.

Further definitions clarify the nature of AI outputs and specific AI methodologies. AI output refers to any content generated by an AI tool. Generative AI is a form of AI that produces content based on user inputs, while a Large Language Model is a specific type of generative AI that processes extensive datasets to create context-related outputs. Machine Learning is identified as a form of AI that self-learns without explicit instructions. The policy also defines a Prompt as an instructive command or question that directs AI to perform tasks, highlighting the interactive nature of many AI applications. Importantly, the policy establishes a clear linguistic hierarchy for its statements: 'must' denotes a mandatory requirement, 'should' indicates a recommendation, and 'may' signifies approval, providing clarity on the binding nature of each provision.

Governance and Institutional Framework

The governance structure for AI security within the DWP is clearly delineated, ensuring accountability and oversight. The DWP Chief Security Officer holds the ultimate accountability for the DWP AI Security Policy, bearing responsibility for its ongoing maintenance and regular review. This critical function is managed through the DWP Deputy Director for Security Policy and Central Services, establishing a clear line of authority for policy adherence and evolution. Furthermore, the policy mandates that line managers play a crucial role in ensuring that their employees are fully aware of their responsibilities when engaging with AI tools, thereby embedding accountability at every level of the organisation. This distributed responsibility model aims to foster a culture of security consciousness and compliance across the DWP workforce.

For the approval and oversight of AI tool usage, the policy designates specific governance boards. The Digital Design Authority (DDA) is identified as the lead DWP governance board responsible for approving new digital tools, including AI. Any significant change to the use case of an approved AI tool, such as the introduction of personal data processing where it was not previously involved, requires approval from a relevant governance board. This structured approval process ensures that new AI applications or substantial modifications to existing ones undergo thorough security and data protection assessments before deployment. The DWP Security and Data Protection directorate is tasked with regularly assessing compliance with this policy, including the inspection of systems, information, and documentation, reinforcing a robust framework for continuous monitoring and enforcement.

Key Focus Areas

The policy outlines several critical areas of focus through its mandatory and advisory statements to ensure the secure and responsible use of AI within the DWP. Firstly, it permits the use of approved AI tools and online AI tools accessible on DWP devices where a legitimate business requirement exists. Secondly, for specific sensitive information—classified as OFFICIAL-SENSITIVE or above, personal data, or non-public DWP code—users must obtain explicit approval from the relevant governance board before using it with an AI tool. Uploading such information without prior approval is strictly prohibited. Thirdly, any significant alteration to an approved AI tool's use case, particularly if it involves processing personal data, must also receive governance board approval.

Data protection and ethical considerations are paramount. The policy mandates adherence to the Data Protection Impact Assessment (DPIA) process when AI tools process personal data, are introduced into existing processes involving personal data, or their outputs affect individuals. Similarly, an Equality Analysis is required when AI tools process personal data related to protected characteristics, in line with the Equality Act 2010. The policy also addresses access to online AI tools, stating they may initially be blocked but can be unblocked upon a business need request. Crucially, users must not attempt to access DeepSeek AI on DWP devices. All interactions with AI tools must adhere to DWP standards of behaviour, and users must ensure the accuracy of data provided to AI tools and rigorously check the accuracy, reliability, and credibility of AI outputs to prevent misinformation or bias. Finally, AI tools that significantly influence public decision-making or directly interact with the public must be logged on the Algorithmic Transparency Recording Standard (ATRS), with an exemption process available for strong justifications not to disclose. Users must also declare AI tool use for official business if requested, for instance, through Freedom of Information (FOI) or Subject Access Requests (SAR).

Implementation Framework

The implementation of the DWP AI Security Policy relies on a clear distribution of responsibilities and a robust framework for compliance. The policy explicitly states that it is the responsibility of all DWP employees, whether permanent or temporary, as well as suppliers and third parties using DWP devices or licensed software, to be aware of and comply with DWP’s security policies and standards. This broad scope ensures that anyone interacting with DWP systems or data, directly or indirectly, is bound by the policy's provisions. Line managers are tasked with a crucial role in ensuring that their teams understand and adhere to these responsibilities, acting as the first line of defence in promoting secure AI practices. The policy underscores that the DWP Information Management Policy also applies when using AI tools, reinforcing a holistic approach to information governance.

To facilitate effective implementation, the policy mandates specific actions for users and management. Users are responsible for reporting any misuse of AI tools to their line manager and, if necessary, to the Security Incident Response Team. Line managers, in turn, are responsible for taking appropriate action in cases of non-compliance, as detailed in the DWP Discipline Policy. This clear escalation path ensures that security incidents are addressed promptly and consistently. Furthermore, the policy requires that AI tools be used in a manner that upholds data protection principles and individual rights, referencing internal DWP guidance on Artificial Intelligence and Data Protection, and for suppliers, guidance from the Information Commissioner's Office (ICO) on explaining decisions made with AI. This comprehensive framework aims to embed secure and ethical AI practices throughout the DWP's operations.

Monitoring and Evaluation

Monitoring and evaluation are integral components of the DWP AI Security Policy, designed to ensure continuous compliance and adaptation to evolving risks. The DWP Security and Data Protection directorate is explicitly tasked with regularly assessing for compliance with this policy. This involves a proactive approach where the directorate may need to inspect systems, information, and documentation. All DWP employees, including temporary staff, and external parties such as suppliers and third parties who use DWP devices or licensed software, are required to fully support these assessment activities. This comprehensive oversight mechanism ensures that adherence to the policy is not merely a one-time declaration but an ongoing, verifiable commitment across the entire scope of the DWP's operations.

Beyond formal assessments, the DWP also employs broader monitoring capabilities to ensure policy adherence. The policy states that the DWP may monitor both business and personal use of DWP information and communication systems. This monitoring is conducted to ensure compliance with all DWP policies and standards, including this AI Security Policy. Further details regarding this monitoring are provided in the DWP Employee Privacy Notice, ensuring transparency about how user activities are observed. This dual approach of targeted compliance assessments by the Security and Data Protection directorate and broader system monitoring reinforces the DWP's commitment to maintaining a secure and compliant environment for AI tool usage, allowing for early detection of potential breaches or areas requiring improvement.

Penalties, Liability, and Appeals

The DWP AI Security Policy establishes clear consequences for non-compliance, emphasizing the serious nature of security breaches and policy violations. All DWP employees, whether permanent or temporary, along with suppliers and third parties utilizing DWP devices or licensed software, are expected to be fully aware of and adhere to DWP’s security policies and standards. Failure to comply with these policies can lead to significant repercussions. Specifically, the policy states that failure to report a security incident, whether actual or potential, could result in disciplinary action. In the most severe circumstances, such non-compliance or failure to report could ultimately lead to dismissal, underscoring the critical importance of security vigilance and prompt reporting.

A "security incident" is broadly defined as the attempted or actual unauthorised access, use, disclosure, modification, loss, or destruction of a DWP asset (or a supplier asset providing service to the Authority) in violation of security policy. This includes actions that are actual, suspected, accidental, deliberate, or attempted. DWP users are mandated to report security incidents as soon as possible via the DWP Security Incident Referral Webform, while third parties and suppliers must follow the DWP Security Incident Management Standard (SS-014). In cases where non-compliance is identified, line managers are responsible for taking appropriate action in accordance with the DWP Discipline Policy. The policy also provides an avenue for exceptions: an exception to policy may be requested if a compelling business case can be made to undertake an activity that would otherwise be non-compliant with DWP security policies and standards. This mechanism allows for flexibility in exceptional circumstances, provided it undergoes proper review and approval.

Relationship to Other Instruments

The DWP Artificial Intelligence Security Policy does not exist in isolation but is intricately linked with a broader ecosystem of DWP policies and UK legal frameworks. It is explicitly stated to be part of a suite of policies designed to promote consistency across the Department and its supplier base regarding security controls. These security policies are cross-referenced where necessary, ensuring they can be confidently used together to form a cohesive security posture. Specifically, the policy refers to the DWP Security Classification Policy for guidance on handling data classified as OFFICIAL-SENSITIVE or above, ensuring that AI tool usage aligns with established information classification protocols. Furthermore, the DWP Information Management Policy is directly applicable when using AI tools, reinforcing comprehensive data governance practices.

Beyond internal DWP policies, the AI Security Policy is also situated within the context of wider UK government initiatives and legal requirements. It explicitly states that it does not replace legal or regulatory requirements, implying that compliance with this policy must also ensure adherence to external laws. The policy mandates an Equality Analysis where personal data relating to protected characteristics is processed by an AI tool, in line with the Equality Act 2010. It also references the Algorithmic Transparency Recording Standard (ATRS), a UK government initiative for public sector bodies to disclose their use of algorithms. While not explicitly mentioned as a direct reference within the DWP policy itself, the broader UK government context, as highlighted by other sources, indicates alignment with the AI Playbook for the UK Government and the government's overall approach to AI regulation, which emphasizes secure and responsible use across government departments. The policy also refers to internal DWP guidance on Artificial Intelligence and Data Protection and, for suppliers, guidance from the Information Commissioner's Office (ICO) on explaining decisions made with AI, demonstrating its connection to data protection legislation like UK GDPR.

International Alignment

While the DWP Artificial Intelligence Security Policy is an internal departmental document for the UK's Department for Work and Pensions, its underlying principles and the broader UK government's approach to AI security inherently reflect international considerations. The policy itself focuses on operational security within the DWP, ensuring that its specific use of AI tools aligns with national standards. However, the UK government's overarching strategy for AI, as articulated in documents like the Artificial Intelligence Playbook for the UK Government and its "pro-innovation approach to AI regulation," is developed with an awareness of global AI governance trends and the need for international cooperation.

The UK government's commitment to secure and resilient AI technologies and services, as highlighted by the Government AI Security Team, is informed by principles such as "Secure by Design" and compliance with the government’s Cyber Security Standard. These principles often draw from international best practices and standards, such as those from NIST or ISO, even if not explicitly cited within the DWP's internal policy. Therefore, while the DWP policy is tailored for a specific UK government department, its adherence contributes to the UK's broader national security posture concerning AI, which is developed within a global context of evolving AI risks and regulatory landscapes, aiming for interoperability and shared understanding with international partners.

Implementation Timeline

MilestoneDateNotes
Policy Last Updated2026-08-07This date indicates the latest update or scheduled review date for the policy document. The policy is currently in force.
Ongoing ComplianceContinuousAll DWP employees, contractors, suppliers, and third parties must continuously comply with the policy's mandatory and advisory elements.
Regular Compliance AssessmentsOngoingThe DWP Security and Data Protection directorate conducts regular assessments for compliance with the policy.

Compliance Checklist

CheckRequired Action
Use of Approved AI ToolsOnly use approved AI tools and online AI tools on DWP devices where there is a business requirement.
Approval for Sensitive DataObtain explicit approval from the relevant governance board before using OFFICIAL-SENSITIVE data, personal data, or non-public DWP code with an AI tool.
Significant Change ApprovalEnsure any significant change to an approved AI tool's use case (e.g., new use of personal data) is approved by a relevant governance board.
Data Protection Impact Assessment (DPIA)Follow the DPIA process when using AI to process personal data, introducing AI into processes with personal data, or using AI output that affects people.
Equality AnalysisConduct an Equality Analysis if an AI tool processes personal data relating to protected characteristics, in line with the Equality Act 2010.
Online AI Tool AccessSubmit a request to unblock online AI tools if there is a business need to access a blocked tool.
Prohibited AI ToolsDo not attempt to access DeepSeek AI on DWP devices.
Standards of BehaviourAdhere to DWP standards of behaviour when interacting with AI tools.
Data Accuracy (Input)Ensure, to the best of your ability, that data provided to AI tools is accurate.
Output VerificationCheck the accuracy, reliability, and credibility of AI output to verify it does not contain misinformation or bias.
Algorithmic Transparency Recording Standard (ATRS)Log AI tools on the ATRS if they significantly influence public decision-making or directly interact with the public, unless an exemption is justified.
Declaration of AI UseDeclare the use of AI tools for official business if requested (e.g., FOI, SAR).
Information Management Policy AdherenceEnsure the DWP Information Management Policy applies when using AI tools.
Data Protection Principles & RightsUse AI tools in a way that ensures data protection principles and individual rights are upheld.
Reporting MisuseReport misuse of AI tools to your line manager and, if required, to the Security Incident Response Team.
Supplier Compliance (Annex A)Suppliers and their third parties must comply with specific AI security requirements when working for DWP, including data handling, DPIA, accuracy, transparency, and data protection.

Sources and References

SourceType
Artificial Intelligence Security Policy (DWP)official
Artificial Intelligence - UK Government Securitygovernment
Launching the Artificial Intelligence Playbook for the UK Governmentgovernment
Artificial Intelligence Playbook for the UK Government (PDF)official

© Regulations.AI — created on 06-Sep-2026 using Gemini 2.5 Flash