Cybersecurity organisation CREST has launched a new accreditation aimed at helping organisations assess whether providers have the expertise to test AI-enabled systems securely, as generative AI and large language models become embedded in business applications. The Security Testing of AI standard sets independently assessable requirements for cybersecurity service providers, giving buyers a way to assess suppliers’ technical expertise, testing methodologies and governance. CREST said the accreditation addresses a growing gap as AI moves from experimentation into applications, products and business processes. Buyers have had limited ways to distinguish providers with specialist AI security testing capabilities from those simply claiming expertise. The standard assesses practitioner competence, testing methodologies, governance and quality controls, technical approaches and tooling, and processes for identifying and evaluating AI-specific security risks. Providers must also produce evidence supporting their testing conclusions. The approach takes a system-level view of AI security rather than treating the underlying model as the only attack surface. Testing can encompass applications, prompts and system instructions, retrieval mechanisms, data sources, memory, tools, plugins, APIs, orchestration layers and downstream systems affected by AI-generated outputs. That broader approach is increasingly relevant to connected products and services, where an AI model may sit alongside multiple applications, APIs, data sources and Cloud or Edge components. CREST chief executive Nick Benson said the organisation’s members had identified a need for greater visibility into the AI testing credentials of cybersecurity providers. “Offering security testing of AI systems and demonstrating the ability to deliver it effectively are two different things,” he said. The accreditation is the latest element of CREST’s expanding AI assurance programme. In July, the organisation introduced an AI-Enabled Penetration Testing standard covering how providers use AI to deliver cybersecurity services. The latest standard instead focuses on their ability to test AI-enabled systems themselves. CREST research cited in the announcement