Qualysec
Blog

What the CREST AI Charter Means for Enterprise Security Buyers

See how the CREST AI Charter helps you choose reliable AI security vendors, cut through vendor hype, and protect your enterprise from hidden risks.

Published on September 23, 2026
Read Time: 13 min
CONNECT WITH US

The CREST AI Charter gives security buyers a clear way to understand how cybersecurity providers should use AI in their institutions. You should know how a CREST AI-accredited provider handles your data, validates AI-generated outputs, manages third-party models, and maintains human oversight. The charter addresses these concerns through a set of principles for responsible AI use.

According to the CREST 2026 research of 62 cybersecurity providers across 19 countries, 69% of organizations are now using AI in penetration testing. 76% have increased their use in the past few years. This growing adoption makes transparency and accountability increasingly important when assessing AI-enabled security services.

In this blog, we are going to discuss what the CREST AI Charter means for enterprise security buyers. We will also explore its nine principles, clarify what signatory status demonstrates, and compare the Charter with CREST AI Accreditation. The article also covers the evidence buyers should request from AI-enabled security providers.

Key Takeaways

  • There are nine principles outlined in the CREST AI Charter for the use of AI in cybersecurity services.
  • The CREST AI Charter is a voluntary undertaking and is not intended to substitute independent technical assessment.
  • CREST AI Accreditation gives independent assurance on a provider’s compliance with AI requirements.
  • You need to ask providers about their AI usage, handling of your data, management of third-party models, and validation of AI-based outputs.
  • Understanding AI governance, data protection, human supervision, and CREST AI Accreditation will enable you to better evaluate providers.

What Is the CREST AI Charter And When Was It Introduced?

The CREST AI Charter is an industry-wide global initiative aimed at promoting the responsible application of AI across cybersecurity services. Launched by CREST International in June 2026, it brings together more than 100 cybersecurity providers, representing over 10% of CREST’s worldwide membership.

The Charter is designed as a voluntary public commitment rather than a certification. The aim is to set the standard on ethical usage of AI, governance, transparency, and accountability in the cybersecurity sector.

What Are The Nine Principles CREST Announced For AI-Enabled Activities?

CREST’s nine principles provide a foundation for responsible AI use across cybersecurity services. They address the areas of importance where AI integrates into security delivery. Such as accountability, transparency, human oversight, data protection, secure development, third-party dependencies, and resiliency. 

These principles can help you understand how providers should address AI-related risks during security engagements.

1. Establishing Clear AI Ownership and Oversight

There must be clarity of responsibility and governance for the use of AI. Providers need to be aware of the reasons for using AI as well as the potential risks.

  • Define its purpose: Identify where AI is being implemented and its function in the service.
  • Evaluate potential impact: Think about how it will affect service delivery, client results, data, decisions, and operational risk.
  • Use proportionate controls: Apply governance and testing that match the nature and risk of the AI activity.

2. Making AI Usage Visible to Clients

Make sure your security provider has made you aware of the role AI plays in a security service. Clear disclosure helps buyers assess its role, benefits, and limitations.

  • Disclose relevant AI use: Explain where AI tools, technologies, methodologies, or automation are used.
  • Identify external AI: Make relevant third-party AI solutions visible where they affect the engagement.
  • Explain limitations: Clarify what AI does and where professional judgement remains necessary.

3. Keeping AI Activities Traceable and Reviewable

AI-supported work should remain documented and capable of being reviewed. This helps providers to show the impact of AI in an engagement.

  • Record AI use: Capture the context and application of AI within service delivery.
  • Maintain validation evidence: Record the validation or review of the outputs generated by AI.
  • Support assurance: Keep the necessary documentation for internal or external review.

4. Keeping AI Within Defined Boundaries

The employment of AI must be confined to clearly specified parameters. The professionals who are qualified and have relevant experience must control and regulate it.

  • Set limits of operation: Bound AI to authorized uses and controls.
  • Keep human supervision: Keep competent people supervising the activities related to AI.
  • Support intervention: Provide staff with an opportunity to review, challenge, and intervene if AI causes inappropriate outcomes.

5. Controlling Client Data and Its Whereabouts

AI-powered services can involve accessing or handling sensitive client data. So it is vital to have transparent data handling protocols.

  • Explain data use: Communicate with clients about the ways their data is being handled using AI services.
  • Explain model training: Indicate if it’s the client data or prompts that are used to train models.
  • Discuss data location: Describe the relevant arrangements for data storage, processing, and cross-border transfers.

6. Protecting AI-Processed Information

AI does not reduce the need to protect confidential client information. Providers should apply appropriate safeguards to information processed through AI-enabled services.

  • Manage access: Ensure that client information and data relating to AI is accessible only to authorized individuals or systems.
  • Secure prompts and outputs: Ensure that prompts and generated outputs are kept secure and that any AI-produced artefacts are not disclosed to others.
  • Implement appropriate safeguards: Implement suitable technical and organizational controls throughout the service.

7. Building and Maintaining AI Tools Securely

Cybersecurity providers also have to take care of the appropriate security of the AI tools they use throughout their development and use.

  • Securely develop: Use appropriate security practices for the development of AI tooling and supporting elements.
  • Test AI tools: Evaluate AI tools before and while they are being used.
  • Handle changes: Continue reviewing and maintaining AI tooling throughout its lifecycle.

8. Managing Risks From External AI Dependencies

Third-party AI models, platforms, and providers can add other risks to security services. The providers must have an understanding of the material’s external dependencies.

  • Understand dependencies: Acknowledge the third-party AI technologies and providers that are necessary.
  • Identify associated risks: Take into account security risks, compliance, risks to resilience, and operational risks.
  • Maintain supplier oversight: Apply appropriate governance and risk management to relevant third parties.

9. Preparing for AI Disruption and Service Continuity

Providers should consider how an AI failure or disruption could affect service delivery. Material AI dependencies should not become unmanaged points of failure.

  • Identify critical dependencies: Determine which AI components are important to delivering the service.
  • Prepare fallback arrangements: Where practical, maintain proportionate fallback or degraded operating arrangements.
  • Explain disruption impacts: Communicate how significant AI disruptions could affect service delivery and recovery.

Get CREST-Accredited Penetration Testing Services

Qualysec delivers CREST-accredited VAPT services with real-world attack simulations, validated findings, and actionable remediation reports.

Request a Quote



CREST Member

Why Does the CREST AI Charter Matter to Enterprise Buyers?

The CREST AI Charter allows you to gain a better way to measure how an AI cybersecurity provider implements AI. Rather than depending on the broad concept of “AI-powered,” you can look into tangible issues. Such as transparency, governance, data management, human oversight, and accountability.

  • Greater Transparency About AI Use

When a provider uses AI during your security engagement, you should know where and how it is involved. The Charter gives you a basis for asking what the AI does, what information it processes, and where human professionals remain involved.

  • Understand AI usage: Ask which AI tools, models, or automated processes are used during your engagement.
  • Check third-party involvement: Find out whether external AI platforms or models are part of the service.
  • Confirm human validation: Ask how professionals review AI-generated outputs before they influence your findings or deliverables.

This helps you understand the actual role of AI instead of relying on a general “AI-powered” claim.

  • Clearer Expectations for Responsible AI

The Charter also gives you a practical reference when assessing whether a provider manages AI responsibly. Its principles cover areas such as governance, human oversight, data control, secure development, and third-party risk.

You can look for evidence that your provider:

  • Assigns clear responsibility for AI-enabled activities and related risks.
  • Keeps qualified professionals involved in reviewing and controlling AI-supported work.
  • Protects your information and explains how AI systems handle sensitive data.
  • Maintains appropriate controls around AI tools and third-party dependencies.

This makes it easier for you to assess responsible AI practices during vendor due diligence.

  • Better Questions During Security Procurement

The nine principles can help you ask more specific questions when evaluating an AI-enabled security provider. Rather than simply asking whether a provider “uses AI responsibly”, you can examine how that AI actually works within your engagement.

What Should Enterprise Buyers Know About CREST AI Charter Signatory Status?

If your cybersecurity service provider is a signatory to CREST’s AI Charter, then they have made a public pledge regarding the responsible use of AI for cybersecurity. You should understand what that commitment covers and what it does not confirm.

  • A Public Commitment to Responsible AI

Signing the CREST AI Charter shows that a provider supports CREST’s principles for responsible AI use in cybersecurity. It gives you a visible indication that the organisation recognises the importance of transparency, accountability, and responsible AI practices.

For you as a buyer, this can provide a useful starting point when discussing how a provider uses AI during your security engagement.

  • A Growing Community of Signatories

The Charter brings together cybersecurity organisations from across the global industry. Signatories include providers involved in areas such as CREST penetration testing, incident response, vulnerability assessment, and threat intelligence.

This gives you a broader industry reference point when assessing how potential providers approach responsible AI use.

  • What Signatory Status Can Tell You

A provider’s signatory status can help you identify organisations that have publicly committed to responsible AI practices. You can use this as one part of your vendor due diligence when evaluating AI-enabled security services.

You can then ask the provider for evidence of how it puts those commitments into practice, such as:

  • How AI is used during your engagement.
  • How your data is handled by AI tools.
  • Where human professionals review AI-generated outputs.
  • How third-party AI tools and dependencies are managed.
  • What internal controls support responsible AI use.
  • What Signatory Status Does Not Confirm

Signatory status should not be treated as proof that a provider has passed an independent technical assessment of its AI systems or security processes. The Charter is a voluntary commitment, while CREST’s AI accreditations provide independently assessable requirements for specific areas of AI-enabled cybersecurity.

How Is the CREST AI Charter Different From CREST AI Accreditation?

The CREST AI Charter and CREST AI Accreditation both address responsible AI use, but they give you different types of information when assessing a cybersecurity provider.

  • The AI Charter Shows Commitment

The Charter is a voluntary commitment that lets a provider publicly demonstrate support for responsible, transparent, and accountable AI use.

As a buyer, you can use signatory status to:

  • Check whether the provider has publicly committed to CREST’s AI principles.
  • Start conversations about how AI is used in your engagement.
  • Ask for evidence of how those principles are applied in practice.
  • AI Accreditation Provides Independent Assessment

CREST AI Accreditation goes further by assessing providers against defined requirements. In September 2026, CREST announced its first 10 AI-Enabled Penetration Testing accredited providers.

This can give you additional evidence about AI governance, human involvement,  technical controls, and independent assurance.

  • What Does the Difference Mean

Area AI Charter AI Accreditation
Purpose Public commitment to responsible AI Independent assessment against defined requirements
Key Difference The provider supports CREST’s AI principles The provider has undergone assessment for applicable AI requirements
Verification Voluntary signatory status CREST accreditation process
Buyer use Useful for initial vendor due diligence Additional assurance during provider selection
Scope Broad responsible AI principles Specific AI governance or service requirements

What Evidence Should Enterprise Security Buyers Request From AI-Enabled Security Providers?

When selecting an AI-enabled security provider, it’s important to examine the provider’s security capabilities beyond its AI capabilities. Seek practical examples and evidence of control of AI and how your information is safeguarded. Also check how professionals can validate the work produced by AI.

  • Request policies for AI governance: Ask how the AI tools are selected, who approves them, and how they are being monitored and controlled during your security engagement.
  • Data protection controls: Understand how data is stored, accessed, encrypted, and utilized in your code, testing data, prompts, and vulnerability information.
  • Human validation: Ask how security professionals review AI-generated findings before they impact your assessment and final report.
  • Third-party AI dependencies: Identify the third-party AI systems or models used and how the security and data risks are addressed.
  • CREST accreditation: Check the official CREST Marketplace for relevant, active company-level accreditations and applicable AI testing specialisms.
  • Evidence of implementation: Policies, process documentation, sample deliverables, or other evidence demonstrating that the stated controls with respect to AI are in practice.

Need a CREST-accredited AI cybersecurity provider?

Choose a partner that helps you identify and fix real security risks before real hackers do.

Talk to an Expert

Ai Cybersecurity

Conclusion

The CREST AI Charter establishes a crucial baseline for accountability, transparency, and governance in an increasingly automated cybersecurity market. By establishing clear operational boundaries, the charter empowers enterprise buyers to demand responsible innovation without compromising security. Pairing these foundational principles with verified CREST accreditations and stringent procurement checks ensures organizations can confidently leverage AI-driven security testing while maintaining total data sovereignty and regulatory compliance.

FAQs

What is the CREST AI Charter?

The CREST AI Charter is an industry-wide global initiative launched by CREST International to promote the responsible, ethical, and transparent use of artificial intelligence across cybersecurity services. It functions as a voluntary public commitment outlining nine core principles for governance, data protection, and human oversight.

What is the difference between the CREST AI Charter and CREST AI Accreditation?

The CREST AI Charter is a voluntary public commitment demonstrating an organization’s alignment with responsible AI principles for initial vendor screening. In contrast, CREST AI Accreditation involves a rigorous, independent technical assessment of a provider’s governance, technical controls, and specific AI-enabled service capabilities.

Why does the CREST AI Charter matter to enterprise security buyers?

The Charter gives enterprise buyers a structured framework to evaluate how cybersecurity providers govern, secure, and validate AI technologies beyond broad marketing claims. It establishes clear criteria for assessing transparency, data handling, third-party model risks, and accountability during vendor due diligence.

What evidence should enterprise security buyers request from AI-enabled security providers?

Buyers should request formal AI governance policies, data protection controls detailing how prompts and testing data are handled, and proof of human validation where qualified professionals review AI-generated findings. Additionally, buyers should verify active company accreditations via the official CREST Marketplace.

How do organizations secure AI-driven systems against emerging threats?

Organizations employ specialized AI security testing, such as evaluating Large Language Models (LLMs). AI agents are tested against prompt injection, data poisoning, and model theft, mapped against frameworks like NIST, the EU AI Act, and MITRE ATLAS.

Pabitra Kumar Sahoo

About Pabitra Kumar Sahoo

Pabitra Kumar Sahoo is the Co-Founder and Chief Operating Officer (COO) at Qualysec. With a deep commitment to elevating global cybersecurity standards, he directs corporate operations and service strategy, helping enterprises mitigate compliance debt and defend their digital infrastructure through elite, human-led penetration testing.

Leave a Comment.

Your email address will not be published. Required fields are marked *

Related Blogs

Subscribe to Newsletter

Get the latest cybersecurity insights, compliance tips, and vulnerability reports delivered directly to your inbox.