← Latest reporting

ISO/IEC 27090 should start a threat gap assessment, not a compliance claim

The AI cybersecurity standard is entering publication. Teams can use its threat catalogue now, but should record the risks and actors it does not cover before calling the result complete.

Policy, Standards and GovernanceAI Capability Frontier
A flat woodcut accordion strip representing an AI lifecycle has rough threat-shaped holes, several patched and two deliberately left uncovered.
Conceptual illustration generated with AI under editorial direction; it does not depict a real event.

What happened

ISO lists ISO/IEC 27090 at publication stage for October 2026, with guidance on AI-specific cybersecurity threats and mitigations across the system lifecycle.

Why it matters

A new standard can sharpen a control review without proving conformity, covering every threat source or replacing local evidence about models, data, suppliers and users.

ISO’s catalogue entry places ISO/IEC 27090 at publication stage for October 2026. It describes guidance for detecting and mitigating cybersecurity threats specific to AI systems across their lifecycle, complementing ISO/IEC 27001 and 27002. The listed examples include data poisoning, model theft and threats introduced during retraining.

Publication is not certification. The catalogue does not show that an organisation has mapped its own assets, tested controls or resolved residual risk. Nor does an October edition date supply an exact operational deadline for every adopter.

Run a bounded threat gap assessment

Start with one deployed AI service. Map model, training and retrieval data, prompts, tool permissions, interfaces, suppliers and monitoring to the threat categories. For each material threat, record an owner, preventative control, detection evidence, response path and test date.

Then add an explicit uncovered-risk register. Independent commentary on the draft says its emphasis is deliberate active attack and flags less complete treatment of accidental events, natural hazards, insiders and harmful uses of AI against other parties. Those observations are commentary on a draft, not an authoritative interpretation of the final text, but they are useful challenge questions.

The counterargument is that teams should wait for the final text. Procurement or certification language should. A reversible inventory and gap assessment need not: label the mapping provisional, cite the edition reviewed and recheck it after publication.

The immediate decision is to pilot a threat-to-evidence map on one system while prohibiting “ISO/IEC 27090 compliant” claims until the final standard, applicable conformity route and local evidence have been reviewed.