The CREST AI Charter gives security buyers a clear way to understand how cybersecurity providers should use AI in their institutions. You should know how a CREST AI-accredited provider handles your data, validates AI-generated outputs, manages third-party models, and maintains human oversight. The charter addresses these concerns through a set of principles for responsible AI use.
According to the CREST 2026 research of 62 cybersecurity providers across 19 countries, 69% of organizations are now using AI in penetration testing. 76% have increased their use in the past few years. This growing adoption makes transparency and accountability increasingly important when assessing AI-enabled security services.
In this blog, we are going to discuss what the CREST AI Charter means for enterprise security buyers. We will also explore its nine principles, clarify what signatory status demonstrates, and compare the Charter with CREST AI Accreditation. The article also covers the evidence buyers should request from AI-enabled security providers.
Key Takeaways
- There are nine principles outlined in the CREST AI Charter for the use of AI in cybersecurity services.
- The CREST AI Charter is a voluntary undertaking and is not intended to substitute independent technical assessment.
- CREST AI Accreditation gives independent assurance on a provider’s compliance with AI requirements.
- You need to ask providers about their AI usage, handling of your data, management of third-party models, and validation of AI-based outputs.
- Understanding AI governance, data protection, human supervision, and CREST AI Accreditation will enable you to better evaluate providers.
What Is the CREST AI Charter And When Was It Introduced?
The CREST AI Charter is an industry-wide global initiative aimed at promoting the responsible application of AI across cybersecurity services. Launched by CREST International in June 2026, it brings together more than 100 cybersecurity providers, representing over 10% of CREST’s worldwide membership.
The Charter is designed as a voluntary public commitment rather than a certification. The aim is to set the standard on ethical usage of AI, governance, transparency, and accountability in the cybersecurity sector.
What Are The Nine Principles CREST Announced For AI-Enabled Activities?
CREST’s nine principles provide a foundation for responsible AI use across cybersecurity services. They address the areas of importance where AI integrates into security delivery. Such as accountability, transparency, human oversight, data protection, secure development, third-party dependencies, and resiliency.
These principles can help you understand how providers should address AI-related risks during security engagements.
1. Establishing Clear AI Ownership and Oversight
There must be clarity of responsibility and governance for the use of AI. Providers need to be aware of the reasons for using AI as well as the potential risks.
- Define its purpose: Identify where AI is being implemented and its function in the service.
- Evaluate potential impact: Think about how it will affect service delivery, client results, data, decisions, and operational risk.
- Use proportionate controls: Apply governance and testing that match the nature and risk of the AI activity.
2. Making AI Usage Visible to Clients
Make sure your security provider has made you aware of the role AI plays in a security service. Clear disclosure helps buyers assess its role, benefits, and limitations.
- Disclose relevant AI use: Explain where AI tools, technologies, methodologies, or automation are used.
- Identify external AI: Make relevant third-party AI solutions visible where they affect the engagement.
- Explain limitations: Clarify what AI does and where professional judgement remains necessary.
3. Keeping AI Activities Traceable and Reviewable
AI-supported work should remain documented and capable of being reviewed. This helps providers to show the impact of AI in an engagement.
- Record AI use: Capture the context and application of AI within service delivery.
- Maintain validation evidence: Record the validation or review of the outputs generated by AI.
- Support assurance: Keep the necessary documentation for internal or external review.
4. Keeping AI Within Defined Boundaries
The employment of AI must be confined to clearly specified parameters. The professionals who are qualified and have relevant experience must control and regulate it.
- Set limits of operation: Bound AI to authorized uses and controls.
- Keep human supervision: Keep competent people supervising the activities related to AI.
- Support intervention: Provide staff with an opportunity to review, challenge, and intervene if AI causes inappropriate outcomes.
5. Controlling Client Data and Its Whereabouts
AI-powered services can involve accessing or handling sensitive client data. So it is vital to have transparent data handling protocols.
- Explain data use: Communicate with clients about the ways their data is being handled using AI services.
- Explain model training: Indicate if it’s the client data or prompts that are used to train models.
- Discuss data location: Describe the relevant arrangements for data storage, processing, and cross-border transfers.
6. Protecting AI-Processed Information
AI does not reduce the need to protect confidential client information. Providers should apply appropriate safeguards to information processed through AI-enabled services.
- Manage access: Ensure that client information and data relating to AI is accessible only to authorized individuals or systems.
- Secure prompts and outputs: Ensure that prompts and generated outputs are kept secure and that any AI-produced artefacts are not disclosed to others.
- Implement appropriate safeguards: Implement suitable technical and organizational controls throughout the service.
7. Building and Maintaining AI Tools Securely
Cybersecurity providers also have to take care of the appropriate security of the AI tools they use throughout their development and use.
- Securely develop: Use appropriate security practices for the development of AI tooling and supporting elements.
- Test AI tools: Evaluate AI tools before and while they are being used.
- Handle changes: Continue reviewing and maintaining AI tooling throughout its lifecycle.
8. Managing Risks From External AI Dependencies
Third-party AI models, platforms, and providers can add other risks to security services. The providers must have an understanding of the material’s external dependencies.
- Understand dependencies: Acknowledge the third-party AI technologies and providers that are necessary.
- Identify associated risks: Take into account security risks, compliance, risks to resilience, and operational risks.
- Maintain supplier oversight: Apply appropriate governance and risk management to relevant third parties.
9. Preparing for AI Disruption and Service Continuity
Providers should consider how an AI failure or disruption could affect service delivery. Material AI dependencies should not become unmanaged points of failure.
- Identify critical dependencies: Determine which AI components are important to delivering the service.
- Prepare fallback arrangements: Where practical, maintain proportionate fallback or degraded operating arrangements.
- Explain disruption impacts: Communicate how significant AI disruptions could affect service delivery and recovery.
Why Does the CREST AI Charter Matter to Enterprise Buyers?
The CREST AI Charter allows you to gain a better way to measure how an AI cybersecurity provider implements AI. Rather than depending on the broad concept of “AI-powered,” you can look into tangible issues. Such as transparency, governance, data management, human oversight, and accountability.
-
Greater Transparency About AI Use
When a provider uses AI during your security engagement, you should know where and how it is involved. The Charter gives you a basis for asking what the AI does, what information it processes, and where human professionals remain involved.
- Understand AI usage: Ask which AI tools, models, or automated processes are used during your engagement.
- Check third-party involvement: Find out whether external AI platforms or models are part of the service.
- Confirm human validation: Ask how professionals review AI-generated outputs before they influence your findings or deliverables.
This helps you understand the actual role of AI instead of relying on a general “AI-powered” claim.
-
Clearer Expectations for Responsible AI
The Charter also gives you a practical reference when assessing whether a provider manages AI responsibly. Its principles cover areas such as governance, human oversight, data control, secure development, and third-party risk.
You can look for evidence that your provider:
- Assigns clear responsibility for AI-enabled activities and related risks.
- Keeps qualified professionals involved in reviewing and controlling AI-supported work.
- Protects your information and explains how AI systems handle sensitive data.
- Maintains appropriate controls around AI tools and third-party dependencies.
This makes it easier for you to assess responsible AI practices during vendor due diligence.
-
Better Questions During Security Procurement
The nine principles can help you ask more specific questions when evaluating an AI-enabled security provider. Rather than simply asking whether a provider “uses AI responsibly”, you can examine how that AI actually works within your engagement.
What Should Enterprise Buyers Know About CREST AI Charter Signatory Status?
If your cybersecurity service provider is a signatory to CREST’s AI Charter, then they have made a public pledge regarding the responsible use of AI for cybersecurity. You should understand what that commitment covers and what it does not confirm.
-
A Public Commitment to Responsible AI
Signing the CREST AI Charter shows that a provider supports CREST’s principles for responsible AI use in cybersecurity. It gives you a visible indication that the organisation recognises the importance of transparency, accountability, and responsible AI practices.
For you as a buyer, this can provide a useful starting point when discussing how a provider uses AI during your security engagement.
-
A Growing Community of Signatories
The Charter brings together cybersecurity organisations from across the global industry. Signatories include providers involved in areas such as CREST penetration testing, incident response, vulnerability assessment, and threat intelligence.
This gives you a broader industry reference point when assessing how potential providers approach responsible AI use.
-
What Signatory Status Can Tell You
A provider’s signatory status can help you identify organisations that have publicly committed to responsible AI practices. You can use this as one part of your vendor due diligence when evaluating AI-enabled security services.
You can then ask the provider for evidence of how it puts those commitments into practice, such as:
- How AI is used during your engagement.
- How your data is handled by AI tools.
- Where human professionals review AI-generated outputs.
- How third-party AI tools and dependencies are managed.
- What internal controls support responsible AI use.
-
What Signatory Status Does Not Confirm
Signatory status should not be treated as proof that a provider has passed an independent technical assessment of its AI systems or security processes. The Charter is a voluntary commitment, while CREST’s AI accreditations provide independently assessable requirements for specific areas of AI-enabled cybersecurity.
How Is the CREST AI Charter Different From CREST AI Accreditation?
The CREST AI Charter and CREST AI Accreditation both address responsible AI use, but they give you different types of information when assessing a cybersecurity provider.
-
The AI Charter Shows Commitment
The Charter is a voluntary commitment that lets a provider publicly demonstrate support for responsible, transparent, and accountable AI use.
As a buyer, you can use signatory status to:
- Check whether the provider has publicly committed to CREST’s AI principles.
- Start conversations about how AI is used in your engagement.
- Ask for evidence of how those principles are applied in practice.
-
AI Accreditation Provides Independent Assessment
CREST AI Accreditation goes further by assessing providers against defined requirements. In September 2026, CREST announced its first 10 AI-Enabled Penetration Testing accredited providers.
This can give you additional evidence about AI governance, human involvement, technical controls, and independent assurance.
-
What Does the Difference Mean
| Area | AI Charter | AI Accreditation |
| Purpose | Public commitment to responsible AI | Independent assessment against defined requirements |
| Key Difference | The provider supports CREST’s AI principles | The provider has undergone assessment for applicable AI requirements |
| Verification | Voluntary signatory status | CREST accreditation process |
| Buyer use | Useful for initial vendor due diligence | Additional assurance during provider selection |
| Scope | Broad responsible AI principles | Specific AI governance or service requirements |
What Evidence Should Enterprise Security Buyers Request From AI-Enabled Security Providers?
When selecting an AI-enabled security provider, it’s important to examine the provider’s security capabilities beyond its AI capabilities. Seek practical examples and evidence of control of AI and how your information is safeguarded. Also check how professionals can validate the work produced by AI.
- Request policies for AI governance: Ask how the AI tools are selected, who approves them, and how they are being monitored and controlled during your security engagement.
- Data protection controls: Understand how data is stored, accessed, encrypted, and utilized in your code, testing data, prompts, and vulnerability information.
- Human validation: Ask how security professionals review AI-generated findings before they impact your assessment and final report.
- Third-party AI dependencies: Identify the third-party AI systems or models used and how the security and data risks are addressed.
- CREST accreditation: Check the official CREST Marketplace for relevant, active company-level accreditations and applicable AI testing specialisms.
- Evidence of implementation: Policies, process documentation, sample deliverables, or other evidence demonstrating that the stated controls with respect to AI are in practice.
Conclusion
The CREST AI Charter establishes a crucial baseline for accountability, transparency, and governance in an increasingly automated cybersecurity market. By establishing clear operational boundaries, the charter empowers enterprise buyers to demand responsible innovation without compromising security. Pairing these foundational principles with verified CREST accreditations and stringent procurement checks ensures organizations can confidently leverage AI-driven security testing while maintaining total data sovereignty and regulatory compliance.
FAQs
What is the CREST AI Charter?
The CREST AI Charter is an industry-wide global initiative launched by CREST International to promote the responsible, ethical, and transparent use of artificial intelligence across cybersecurity services. It functions as a voluntary public commitment outlining nine core principles for governance, data protection, and human oversight.
What is the difference between the CREST AI Charter and CREST AI Accreditation?
The CREST AI Charter is a voluntary public commitment demonstrating an organization’s alignment with responsible AI principles for initial vendor screening. In contrast, CREST AI Accreditation involves a rigorous, independent technical assessment of a provider’s governance, technical controls, and specific AI-enabled service capabilities.
Why does the CREST AI Charter matter to enterprise security buyers?
The Charter gives enterprise buyers a structured framework to evaluate how cybersecurity providers govern, secure, and validate AI technologies beyond broad marketing claims. It establishes clear criteria for assessing transparency, data handling, third-party model risks, and accountability during vendor due diligence.
What evidence should enterprise security buyers request from AI-enabled security providers?
Buyers should request formal AI governance policies, data protection controls detailing how prompts and testing data are handled, and proof of human validation where qualified professionals review AI-generated findings. Additionally, buyers should verify active company accreditations via the official CREST Marketplace.
How do organizations secure AI-driven systems against emerging threats?
Organizations employ specialized AI security testing, such as evaluating Large Language Models (LLMs). AI agents are tested against prompt injection, data poisoning, and model theft, mapped against frameworks like NIST, the EU AI Act, and MITRE ATLAS.







