ACCA UK Advocates for a Global-Focused AI Cybersecurity Strategy

The Association of Chartered Certified Accountants (ACCA) views a proposed AI cyber code as a promising initial framework for global regulation.

In response to a consultation led by the UK’s Department for Science, Innovation & Technology on an AI cybersecurity code of practice, the ACCA emphasized the government’s role in establishing comprehensive regulatory structures and principles. It also stressed that AI developers should have the freedom to address emerging cyber threats.

However, ACCA cautioned that while the pro-innovation stance of the proposed code, outlined in the government’s white paper, is commendable, it requires safeguards and periodic reassessment. Given the rapidly evolving nature of AI-related cyber risks, a static approach could quickly become obsolete.

ACCA also underscored the risks and implications for small and medium-sized enterprises (SMEs), where a large portion of its members operate. These businesses often face significant challenges in cyber readiness due to limited skills and budgets. ACCA advocates for ensuring that SMEs are protected from cyber risks while also being empowered to leverage AI to enhance business productivity.

Glenn Collins, ACCA UK’s head of technical and strategic engagement, stated:

“ACCA welcomes the consultation’s principle-based approach, as the current understanding of AI encompasses numerous unforeseen scenarios. ACCA, along with its members and partners, will be significantly affected by AI’s integration, particularly in equipping finance professionals with the skills necessary for the modern workplace.”

ACCA warned that compliance with any code entails costs, including indirect expenses related to adherence and the broader supply chain impact. Efforts will be necessary to raise awareness, as well as for monitoring and enforcement.

Narayanan Vaidyanathan, ACCA’s head of policy development, remarked:

“We foresee that such a code will be beneficial for those involved in providing assurance or third-party verification of AI systems. This group is crucial in establishing a trusted AI ecosystem, supplementing the regulatory and legal framework set by policymakers.

“We do not expect this group to be directly subject to the code’s requirements. However, assurance requires benchmarks against well-defined, ideally public, standards—standards that this code could provide. Cyber risks are integral to the assurance of AI systems, and thus, those providing assurance would find such a cyber code and associated standards invaluable.”

In its feedback, ACCA also urged the government to address the skills gap essential for combating cybersecurity risks. It proposed expanding the Apprenticeship Levy into a more versatile ‘Growth and Skills Levy’ to fund shorter-term, accredited training programs that enhance workers’ cybersecurity skills in AI.

Additionally, ACCA suggested that companies should be allowed to increase the allocation of unspent levy funds to their supply chains, recommending an increase from 25% to 40%. This adjustment could potentially unlock millions of pounds for AI skill development.

Ultimately, ACCA stressed that effective cybersecurity for AI requires ongoing training on both current and emerging risks. Without adequate training, standards and frameworks will fail to make a significant impact.

More Articles & Posts