⚡ Quick Summary
Published by the European Union Agency for Cybersecurity (ENISA), this report maps standards that are existing, drafted, under consideration or planned for the cybersecurity of artificial intelligence. It assesses their coverage and standardisation gaps, primarily through the confidentiality, integrity and availability (CIA) model, while also considering a broader account of AI trustworthiness. The report focuses mainly on machine learning and considers AI across its life cycle. It was prepared to contribute to work supporting implementation of the proposed EU AI Act, COM(2021) 206 final.
The report’s central position is that general-purpose information-security and quality-management standards can partially mitigate AI cybersecurity risks because AI is, in essence, software. It identifies ISO/IEC 27001, ISO/IEC 27002 and ISO 9001 as particularly relevant, subject to guidance and system-specific analysis. It also finds that cybersecurity is interdependent with trustworthiness features including data quality, oversight, robustness, accuracy, explainability, transparency and traceability. Its deliverable is an inventory and coverage analysis, followed by eight recommendations directed at organisations, standards-developing organisations and actors preparing for the draft AI Act.
🧩 What’s Covered
The report moves from its scope and terminology to the relevant standards landscape, coverage analysis and recommendations.
- Purpose and audience: Defines the aim as surveying relevant standards, assessing coverage and identifying gaps. It identifies standards-developing organisations and public-sector bodies as primary addressees, with relevance also for researchers, AI developers, cybersecurity specialists, businesses and operators of essential services. It expects familiarity with software development, CIA, vulnerability analysis and risk analysis.
- Scope of AI cybersecurity: Sets out the draft AI Act definition of an AI system and explains its focus on machine learning. It distinguishes cybersecurity of AI from AI used to support cybersecurity and malicious use of AI, then contrasts a narrow CIA-based scope with a broader trustworthiness perspective.
- Standards landscape: Reviews CEN-CENELEC JTC 13 and JTC 21, ETSI and its Industry Specification Group on Security of AI, and ISO/IEC JTC 1 SC 42. It lists published and developing work, including ISO/IEC 27090, ISO/IEC 22989, ISO/IEC 23053, ISO/IEC 42001 and ETSI reports on threat ontology, data supply-chain security and mitigation.
- CIA analysis: Applies confidentiality, integrity and availability to AI-specific attacks. Examples include model and data stealing, model disclosure, evasion through adversarial examples, poisoning, and denial of service using malformed or computationally costly inputs.
- Coverage and gaps: Explains how ISO/IEC 27001, ISO/IEC 27002 and ISO 9001 can contribute, but calls for AI-specific guidance. It identifies incomplete treatment of data and component lineage, ML metrics and testing, continuous learning, hardware and infrastructure, and technologies still under research and development.
- Trustworthiness and conformity assessment: Relates cybersecurity to draft AI Act requirements on data governance, logging, transparency, human oversight, risk and quality management, conformity assessment and robustness. It cautions against duplicate or inconsistent standards for overlapping trustworthiness characteristics.
- Draft AI Act and recommendations: Discusses Article 15’s treatment of resilience, data poisoning, adversarial examples and model flaws. Recommendations include harmonised terminology, system- and sector-specific analysis, support for R&D and benchmarking, assessor competence standards, and coherence with the Cybersecurity Act and proposed Cyber Resilience Act.
💡 Why it matters?
The report helps technical, assurance and policy teams connect familiar information-security and quality-management standards to AI-specific risks rather than treating AI cybersecurity as wholly separate. Its CIA examples offer a practical way to classify risks across models, data and processes, while its broader analysis links security to data governance, logging, oversight, transparency and robustness.
For EU-facing high-risk AI work, it identifies areas where evidence and assessment methods were not yet adequately standardised, notably assessor competences, metrics, testing, data lineage, adversarial examples and poisoning. It also stresses that appropriate controls depend on the intended use and domain of a particular system.
❓ What’s Missing
This is a landscape and gap analysis, not a control implementation manual or a complete conformity-assessment method. It does not prescribe a single set of security measures for individual systems; instead, it says that appropriate measures require system-specific and, where needed, sector-specific analysis. The report explicitly recognises that many technical areas remained immature or under active research and development, including aspects of adversarial robustness, poisoning, continuous learning, metrics and benchmarking. Its regulatory analysis is tied to the proposed, pre-adoption draft AI Act and to anticipated standardisation work and dates current at the time of writing, so readers need to verify subsequent legal and standards developments.
👥 Best For
Standards developers and public bodies preparing AI cybersecurity or conformity-assessment work under the proposed EU AI Act. It is also suited to AI security, risk and quality teams that need to map model, data and process risks to ISO, CEN-CENELEC and ETSI activity, then identify where system-specific analysis is required.
📄 Source Details
CYBERSECURITY OF AI AND STANDARDISATION is a 37-page English report published by the European Union Agency for Cybersecurity (ENISA) in March 2023. The named authors are P. Bezombes, S. Brunessaux and S. Cadzow. The imprint lists ISBN 978-92-9204-616-3, DOI 10.2824/277479 and reference TP-03-23-011-EN-C. The final page displays a different ISBN and DOI, requiring verification.