What happened
ISO/IEC 27090, 'Cybersecurity — Artificial Intelligence — Guidance for addressing security threats and compromises to artificial intelligence systems,' is confirmed as a real, advanced-stage ISO/IEC standard: ISO's own explainer page lists it as 'Under publication' (edition dated 2026), while the standard's catalogue page still shows it as DIS (enquiry phase) and multiple secondary sources reference an 'FDIS 27090:2026.' No page or search result gave a specific publication date falling inside or outside the 2026-09-08–09-14 window, so the exact status-change date could not be established this cycle.
Why it matters
This would be the first dedicated ISO/IEC standard on AI-specific security threats (covering data/model/interface attack surfaces across the AI lifecycle), complementing ISO/IEC 42001 (AI management systems) and ISO/IEC 23894 (AI risk management). Its eventual publication will give organizations a formal, certifiable-adjacent reference for AI security threat guidance distinct from governance/management-system standards — worth tracking closely for the exact publication trigger.
Action needed
Monitor ISO.org catalogue for the formal publication date/edition change; once published, map its nine attack-surface categories against existing AI security control sets (OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF).