ISO/IEC 27090 addresses security threats and compromises that are specific to AI systems across their lifecycle. It can help organisations extend established information-security practices with AI-specific risk work.
What ISO/IEC 27090 covers
ISO/IEC 27090, Cybersecurity - Artificial Intelligence - Addressing security threats and compromises to artificial intelligence systems, is under publication. Its status should be checked again before publication or use in a formal programme.
The standard is intended to help organisations understand the consequences of AI-specific security threats throughout an AI system's lifecycle, including how such threats can be detected and mitigated. It applies to organisations of all sizes and types that develop or use AI systems, including businesses, public bodies and not-for-profit organisations.
Its focus is deliberately narrow: AI-specific security threats and compromises. It does not replace the security work required for the software, infrastructure, networks and services on which an AI system depends.
Established information security remains the foundation
An AI model runs within a broader technical environment and inherits the risks of that environment. Access control, secure architecture, vulnerability management, incident response and logging therefore remain essential.
ISO/IEC 27001 defines the requirements for an information security management system. ISO/IEC 27002 complements it with information-security control guidance and best-practice recommendations. ISO/IEC 27090 can be used to add AI-specific considerations to that established work rather than create a separate security organisation.
This layered approach is consistent with ENISA's framework for good AI cybersecurity practices, which distinguishes cybersecurity foundations, AI-specific cybersecurity and sector-specific cybersecurity.
Extend governance and risk work for AI
ISO/IEC 42001 provides management-system context for responsible AI and lifecycle governance.
AI risk work should consider more than application code. It may need to cover training data, pre-trained components, models, inputs and operational monitoring. Threat modelling can make these dependencies and attack paths visible before deployment and as systems change.
Supply-chain assurance deserves particular attention where systems rely on suppliers. ETSI EN 304 223 includes secure software supply-chain processes for AI model and system development.
AI-specific threats need their own analysis
The public ISO catalogue confirms the lifecycle focus of ISO/IEC 27090, but it does not reproduce the full text of the standard. Organisations should consult the final ISO/IEC text when available for its detailed treatment of threats and mitigations.
The following examples illustrate the kinds of AI-specific security concern that should be considered in threat modelling and risk assessment.
| Security concern | Why it matters |
|---|---|
| Manipulation of training data or pre-trained components | Affected data or components can alter how an AI system behaves. |
| Inputs intended to cause an incorrect result | Carefully designed inputs can cause a model to make mistakes. |
| Confidentiality attacks and model flaws | Sensitive information or system behaviour may be exposed or exploited. |
| Model inversion or membership inference | These are examples of AI-specific attacks to address in threat modelling. |
| Weak monitoring and traceability | Without appropriate records, it is harder to investigate incidents and identify patterns of misuse. |
Controls should be assessed together, not in isolation. Monitoring, review and validation remain important as a system, its data and its operating context change.
Relationship with the EU AI Act
For high-risk AI systems, Article 15 of the EU AI Act requires an appropriate level of accuracy, robustness and cybersecurity throughout the lifecycle. Where appropriate, its technical measures must address AI-specific vulnerabilities, including data poisoning, model poisoning, adversarial examples or model evasion, confidentiality attacks and model flaws.
ISO/IEC 27090 may support engineering and risk-management work relevant to these issues. It does not, by itself, demonstrate conformity with the AI Act.
Standards remain voluntary in this context. A presumption of conformity arises only when a relevant harmonised standard has been assessed and referenced in the Official Journal of the European Union, and only for the legal requirements it covers. The European Commission's AI Act standardisation guidance explains that process.
Complementary standards and guidance
| Source | Relationship to AI system security |
|---|---|
| ISO/IEC 27001 and ISO/IEC 27002 | Provide the ISMS requirements and information-security control guidance that underpin wider security practice. |
| ISO/IEC 42001 | Provides an AI management-system framework and lifecycle governance context. |
| ETSI EN 304 223 | Sets baseline security requirements across secure design, development, deployment, maintenance and end of life, including threat modelling, supply-chain security and logging. |
| ENISA multilayer framework | Supports a layered approach combining foundational, AI-specific and sector-specific cybersecurity practices. |
Using the standard in practice
ISO/IEC 27090 is best understood as a source of structured guidance for AI-specific security analysis. It can help teams use a common language, expand existing threat models and identify where ordinary information-security controls need AI-aware application.
It is not a checklist that removes the need for system-specific risk decisions. Organisations should assess their own models, data, suppliers, interfaces and use cases, then select, test and monitor controls that are proportionate to the risks involved.