Guidelines  ·  2026-09-15

ISO/IEC 27090 (AI-specific security threats guidance) nearing publication — status/date unconfirmed

GuidelinesMedium impactGlobal
ISO/IEC 27090, 'Cybersecurity — Artificial Intelligence — Guidance for addressing security threats and compromises to artificial intelligence systems,' is confirmed as a real, advanced-stage ISO/IEC standard: ISO's own explainer page lists it as 'Under publication' (edition dated 2026), while the standard's catalogue page still shows it as DIS (enquiry phase) and multiple secondary sources reference an 'FDIS 27090:2026.' No page or search result gave a specific publication date falling inside or outside the 2026-09-08–09-14 window, so the exact status-change date could not be established this cycle.
This would be the first dedicated ISO/IEC standard on AI-specific security threats (covering data/model/interface attack surfaces across the AI lifecycle), complementing ISO/IEC 42001 (AI management systems) and ISO/IEC 23894 (AI risk management). Its eventual publication will give organizations a formal, certifiable-adjacent reference for AI security threat guidance distinct from governance/management-system standards — worth tracking closely for the exact publication trigger.
Monitor ISO.org catalogue for the formal publication date/edition change; once published, map its nine attack-surface categories against existing AI security control sets (OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF).
ISO/IEC 27090 explained (ISO insights)ISO/IEC DIS 27090 catalogue page
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →