Guidelines  ·  2026-08-28

ISO/IEC 27090 (Cybersecurity — Artificial Intelligence — Addressing security threats and compromises to AI systems) reaches publication stage

GuidelinesHigh impactGlobal
ISO/IEC 27090 — the first international standard specifically addressing security threats and compromises to AI systems (covering data poisoning, evasion, model extraction, prompt injection, etc. across the AI lifecycle) — completed its Final Draft International Standard (FDIS) ballot on 2026-08-19 and moved to ISO stage 60.00, 'International Standard under publication.' This milestone (vote closure and entry to final publication processing) landed at the boundary of/just before our window and was still being actively reported and analyzed by standards practitioners throughout the 2026-08-21 to 2026-08-27 period; as of research the standard had not yet reached full publication (stage 60.60). It is explicitly informative/guidance (not certifiable) and is developed independently of the EU AI Act's harmonised-standards track (that role falls to CEN/CENELEC's prEN 18282).
This is the flagship international standard purpose-built for AI security threats, expected to be widely referenced alongside ISO/IEC 42001 and NIST AI RMF as a baseline vocabulary/guidance document for AI threat categories and lifecycle risk management. Its imminent publication is a major landmark practitioners have been anticipating since FDIS in 2026.
Monitor for formal publication (stage 60.60) and obtain the published text; begin mapping existing AI security programs to its threat taxonomy and lifecycle guidance in preparation for adoption as a reference framework.
ISO — ISO/IEC 27090 project pageISO/IEC 27090 (Spanish ISO page mirror, stage detail)
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →