Ireland - Cyber Security Guidance on Generative AI

National Cyber Security Centre: Cyber Security Guidance on Generative AI for Public Sector Bodies

Ireland

RAI-IE-NA-NCSCCXX-2023
In Force(In Force)
GuidelineCybersecurity and Model SecurityRisk ManagementGovernance and Oversight
Export PDF

Guidance published by Ireland’s National Cyber Security Centre (NCSC) on 01 June 2023 providing cybersecurity-focused advice for Public Sector Bodies (PSBs) adopting or using Generative AI (GenAI). It sets out recommended risk assessment, access controls, do’s and don’ts for staff use, procurement scrutiny for providers, and operational security measures to limit exposure of sensitive public-sector data.

Overview

The National Cyber Security Centre (NCSC) published “Cyber Security Guidance on Generative AI for Public Sector Bodies” on 01 June 2023. The short advisory (8-page PDF) is aimed at Public Sector Bodies (PSBs) in Ireland considering or using Generative AI (GenAI) tools and platforms. It focuses specifically on cyber security risks and mitigations, while acknowledging broader ethical and governance issues are addressed elsewhere by government. The guidance recommends that GenAI adoption be restricted by default, require a clear business case and prior risk assessment, and be accompanied by usage policies and staff awareness measures. The full guidance is available from the NCSC: Cyber Security Guidance on Generative AI for Public Sector Bodies (NCSC PDF, 01 Jun 2023). Additional contextual government AI policy can be found via Ireland’s National AI Strategy: AI - Here for Good (DETE).

Definitions

Generative AI (GenAI): systems capable of generating text, images, audio, video or code (e.g., chatbots, large language models, diffusion models). Public Sector Bodies (PSBs): government departments, agencies and public-service organisations in Ireland that operate and manage public data and service delivery. Data-in: information entered into GenAI systems (user prompts, documents). Data-out: outputs produced by GenAI (answers, summaries, code, images). Enterprise/self-hosted GenAI: vendor enterprise offerings or on-premises models offering contractual controls over data usage and retention. The guidance explicitly refers to risks such as “hallucination” (inaccurate/confidently-stated outputs), privacy exposure, copyright infringement, and adversarial misuse (e.g., enabling phishing, malware, deepfakes).

Governance and Institutional Framework

The guidance situates NCSC advice within the wider Irish whole-of-government AI workstream, including the National AI Strategy AI - Here for Good and subsequent interim public service AI guidelines issued in January 2024 by the Department of Public Expenditure (DPENDR). NCSC, as part of the Departmental and Government cybersecurity architecture, issues operational cyber security guidance; responsibility for AI governance and ethical frameworks is being developed by other departments. PSBs are expected to integrate this NCSC cyber security advice into their own governance processes, procurement rules, and ICT security baselines. The guidance recommends local approval processes (business case, risk assessment sign-off), the involvement of ICT/security teams in procurement and onboarding, vendor security attestation, and cross-departmental coordination for consistent policy application. For NCSC contact and reporting channels see the NCSC site: NCSC Contact & CSIRT-IE.

Key Focus Areas

The document organises risk and mitigation across several focus areas: (1) Data-in risks — do not enter classified, personal, commercially sensitive, or proprietary material into public GenAI models; (2) Data-out risks — validate outputs for accuracy, bias and copyright; (3) Provider and supply-chain security — require evidence of vendor security measures and certifications; (4) Technical hygiene — enforce MFA, robust passwords, logging, patching and vulnerability management; (5) Operational policy — restrict default access, permit only with approved business case, and require staff training; (6) Misuse by malicious actors — recognise GenAI can be used to craft more convincing phishing, automate social engineering, generate malware code, or create deepfakes; (7) Defensive use — GenAI can aid analysis of logs, threat intelligence and phishing simulation if used under secure controls. The guidance gives a concise “Do & Don’t” list (e.g., “Do validate outputs”, “Don’t use public GenAI services for business purposes”, “Don’t use GenAI to draft government policy or respond to public representations”). This mix of technical, procedural and procurement advice is designed for rapid operational adoption within PSBs while broader ethical and legal issues continue to be developed by other government departments.

Implementation Framework

The NCSC guidance recommends a conservative, risk-based implementation framework: 1) Assess business need — require a documented business case; 2) Conduct an appropriate risk assessment covering data protection/GDPR, cyber security, service continuity, and reputational risk; 3) Choose deployment model — prefer enterprise/self-hosted solutions with contractual protections; 4) Vendor assurance — require proof of security controls and international certifications where possible; 5) Apply technical controls — account security, multi-factor authentication, logging and monitoring, vulnerability management and patching; 6) Data handling rules — disable or periodically delete chat histories, do not use corporate emails for public GenAI unless enterprise option authorised; 7) Staff guidance — publish a ‘Do & Don’t’ brief and run awareness training; 8) Integration with procurement criteria — use NCSC procurement guidance templates to embed security requirements for GenAI suppliers. These steps are designed to be pragmatic and layered, allowing PSBs to pilot securely and scale where the risk posture permits.

Monitoring and Evaluation

Monitoring recommendations include continuous logging and monitoring of GenAI service use, maintenance of audit trails for access and queries, periodic review of provider security attestations, and regular re-assessment of risk as model capabilities and provider policies evolve. PSBs are advised to incorporate GenAI usage into existing incident reporting channels (including CSIRT-IE/NCSC), and to measure both security incidents and accuracy/quality issues (e.g., recorded hallucinations, copyright or privacy breaches). The guidance highlights the need to review controls frequently because model training and provider retention/use policies change rapidly; it also recommends liaising with central government AI governance bodies to align monitoring metrics and report cross-government learnings.

Penalties, Liability, and Appeals

The NCSC guidance itself is advisory and does not establish new statutory penalties. It emphasises that non-compliance with the guidance may expose PSBs to existing legal liabilities (notably data protection/GDPR breaches, potential administrative fines, and contractual liabilities) and to internal disciplinary measures under departmental policies. Where a security incident involves personal data, the Data Protection Commission (Ireland) and applicable GDPR enforcement mechanisms would be relevant. Similarly, obligations under NIS/NIS2 and other regulatory frameworks could trigger enforcement actions independent of this guidance. PSBs should therefore treat the guidance as part of their compliance and governance toolkit and escalate incidents using established legal and internal appeal channels.

Relationship to Other Instruments

This cybersecurity guidance is explicitly positioned as complementary to the National AI Strategy (AI - Here for Good) and to the interim public service AI guidelines published in early 2024. It should be used in conjunction with the NCSC Cyber Security Baseline Standards and the NCSC Guidelines on Cyber Security Specifications for ICT procurement. Legal instruments that interact with the guidance include the GDPR (and Ireland’s Data Protection Act), the NIS/NIS2 cybersecurity frameworks, public procurement rules, and forthcoming EU-level AI legislation. PSBs are advised to integrate NCSC cybersecurity measures with ethical, legal, and procurement assessments mandated by other departments.

International Alignment

The guidance recommends alignment with international best practices and vendor assurance frameworks (e.g., internationally-recognised security certifications). It references cross-government objectives to align with EU developments (such as the EU AI Act and NIS2) and Ireland’s participation in international cybersecurity cooperation. PSBs procuring GenAI services from global vendors should therefore seek contractual commitments that reflect EU data-protection and security expectations and ensure that cross-border data flows are lawfully managed. NCSC’s approach mirrors international security-first AI guidance emphasising risk management, vendor scrutiny and conservative data handling for GenAI.

Implementation Timeline

DateMilestone
2023-06-01Publication of NCSC "Cyber Security Guidance on Generative AI for Public Sector Bodies" (NCSC PDF)
2024-01-09Government approves Interim Guidelines for Use of AI in the Public Service (DPENDR)
2024-11-06National AI Strategy refresh published (DETE)
OngoingContinuous review and update recommended as GenAI and vendor policies evolve; PSBs to integrate guidance into departmental AI governance.

Compliance Checklist

ActionRecommended Status
Documented business case and risk assessment for GenAI useRequired
Restrict access by default; enable only with approvalRequired
Use enterprise/self-hosted vendor offerings where business-critical data involvedRecommended
Prohibit input of classified, personal, commercially sensitive, source code, or network topology data into public GenAIRequired
Vendor security assurance and international certification checksRecommended
Account security: strong passwords and MFARequired
Logging, monitoring and incident reporting integrated with CSIRT-IE/NCSCRequired
Staff guidance and awareness training on Do's and Don'tsRequired
Regular deletion or disabling of chat histories where possibleRecommended
Validation and fact-checking of outputs before use in official documentsRequired

Sources and References

SourceType
Cyber Security Guidance on Generative AI for Public Sector Bodies (NCSC PDF, 01 Jun 2023)Primary Source
NCSC Guidance documents indexPrimary Source
AI - Here for Good: National AI Strategy (DETE)Primary Source
Government press release: Interim Guidelines for Use of AI in the Public Service (09 Jan 2024)Primary Source
Plain English

Ireland's National Cyber Security Centre (NCSC) has published essential cybersecurity guidance for all Irish Public Sector Bodies (PSBs) on how to safely adopt and use Generative AI (GenAI) tools. This advice, issued on June 1, 2023, aims to help government departments and agencies manage the specific cyber risks associated with AI systems that generate text, images, or code.

The guidance applies to all Irish PSBs considering or already using GenAI. It strongly recommends a cautious approach, advising that GenAI adoption should be restricted by default. Before any use, PSBs must establish a clear business need and conduct a thorough risk assessment covering data protection, cybersecurity, and reputational impact.

Key obligations for PSBs include: - **Never input sensitive data:** Do not enter classified, personal, commercially sensitive, or proprietary information into public GenAI models. - **Validate outputs:** Always verify the accuracy, check for bias, and confirm copyright compliance of any GenAI-generated content before use. - **Scrutinise providers:** Demand evidence of strong security measures and international certifications from GenAI vendors, preferring enterprise or self-hosted solutions that offer better data control. - **Train staff:** Implement clear usage policies and provide staff awareness training on the "Do's and Don'ts" of GenAI use.

While this NCSC document is guidance and doesn't introduce new statutory penalties, ignoring its recommendations can expose PSBs to significant existing legal liabilities. This includes potential fines under data protection laws like GDPR, as well as enforcement actions under cybersecurity frameworks such as NIS/NIS2, and internal disciplinary measures. PSBs are expected to integrate this advice into their existing governance, procurement, and ICT security frameworks.

A practical pitfall to be aware of is the rapid evolution of GenAI technology and vendor policies. PSBs must continuously monitor their GenAI usage, review provider security attestations, and reassess risks frequently to stay ahead of new threats and ensure ongoing compliance. This guidance is part of a broader government effort to ensure safe and ethical AI use across the public service.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 10 marked complete

Plain-English obligations under Ireland - Cyber Security Guidance on Generative AI. Not legal advice — verify against the official text before relying on it.

  1. #1CriticalCompliance ChecklistBefore using Generative AI

    Applies to: Public Sector Bodies in Ireland.

    Documented business case and risk assessment for GenAI use
  2. #2CriticalCompliance ChecklistBefore deploying Generative AI

    Applies to: Public Sector Bodies in Ireland.

    Restrict access by default; enable only with approval
  3. #3CriticalCompliance ChecklistBefore using public Generative AI

    Applies to: Public Sector Bodies in Ireland.

    Prohibit input of classified, personal, commercially sensitive, source code, or network topology data into public GenAI
  4. #4CriticalCompliance ChecklistBefore using Generative AI

    Applies to: Public Sector Bodies in Ireland.

    Account security: strong passwords and MFA
  5. #5CriticalCompliance ChecklistUpon Generative AI deployment

    Applies to: Public Sector Bodies in Ireland.

    Logging, monitoring and incident reporting integrated with CSIRT-IE/NCSC
  6. #6CriticalCompliance ChecklistBefore staff use Generative AI

    Applies to: Public Sector Bodies in Ireland.

    Staff guidance and awareness training on Do's and Don'ts
  7. #7CriticalCompliance ChecklistBefore using Generative AI outputs

    Applies to: Public Sector Bodies in Ireland.

    Validation and fact-checking of outputs before use in official documents
  8. #8RecommendedCompliance ChecklistWhen procuring Generative AI

    Applies to: Public Sector Bodies in Ireland.

    Use enterprise/self-hosted vendor offerings where business-critical data involved
  9. #9RecommendedCompliance ChecklistBefore procuring Generative AI

    Applies to: Public Sector Bodies in Ireland.

    Vendor security assurance and international certification checks
  10. #10RecommendedCompliance ChecklistOngoing

    Applies to: Public Sector Bodies in Ireland.

    Regular deletion or disabling of chat histories where possible

© Regulations.AI — created on 13-Jun-2026