ISO and IEC develop standard for securing AI systems throughout their lifecycle

ISO/IEC 27090 sets out a framework for identifying and addressing security threats specific to AI systems, including data poisoning and model theft. The standard is intended to complement existing information security practices and cover risks throughout the AI lifecycle.

ISO and IEC develop standard for securing AI systems throughout their lifecycle

The International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) are preparing to publish ISO/IEC 27090, an international standard focused on cybersecurity threats to artificial intelligence systems. As of 9 October 2026, the standard remained in the final stages before publication.

Titled Cybersecurity – Artificial intelligence (AI) – Addressing security threats and compromises to AI systems, it is designed to help organisations identify threats, assess their implications and select appropriate measures to reduce risks.

The standard addresses attacks that target elements specific to AI, including training data, models and the processes through which systems generate outputs. Examples include data poisoning, in which manipulated training or update data can affect a model’s behaviour, and model theft, which involves attempts to extract or reproduce a model’s capabilities.

ISO/IEC 27090 is intended to work alongside existing cybersecurity frameworks rather than replace them. ISO/IEC 27001 and ISO/IEC 27002 provide broader approaches to information security management and controls, while the new standard focuses on threats associated with AI systems. Organisations can therefore build on established security practices while extending their assessments to cover AI-specific risks.

The standard also takes a lifecycle approach. Security risks can change when models are retrained, updated, connected to new data sources or integrated into new workflows. Operational data may also be reused during training, creating further risks. Organisations will need to reassess their protections as systems and their operating environments change.

ISO/IEC 27090 provides a common reference for organisations developing, procuring and deploying AI systems. It may help developers structure threat assessments and testing, while giving deployers and procurement teams a clearer basis for discussing security requirements.

Go to Top