Guidelines  ·  2026-10-10

ISO/IEC 27090 'Cybersecurity — AI — Addressing security threats and compromises to AI systems' confirmed at ISO stage 60.00 (under publication)

GuidelinesHigh impactGlobal
Confirmed in-window (status reported ~4-9 October 2026): ISO/IEC 27090 has moved to ISO stage 60.00 'International Standard under publication', with final production steps expected within up to seven weeks. This follows earlier unconfirmed 'nearing publication' reports (Sept 2026). The standard gives organisations a structured basis for identifying, understanding and mitigating security threats to AI systems across the lifecycle (data poisoning, model theft, etc.), complementing rather than replacing ISO/IEC 27001/27002 and ISO/IEC 42001.
ISO/IEC 27090 is the first international standard dedicated to AI-specific security threats and compromises, distinct from general ISMS controls. Its formal publication is imminent, so CISOs, AI providers/deployers, auditors and procurement teams in regulated industries face a concrete compliance-preparation window. It also slots into the ISO 27001/42001/27090 stack that third-party AI assurance schemes are already referencing.
Map existing AI threat-modeling and T&E processes to the ISO/IEC 27090 controls; plan how AI assets (training data, models, inference, integrations) will be covered by ISMS extensions when the standard publishes; brief procurement and audit teams on the new obligations.
ISO/IEC 27090 sets out an international standard for AI cybersecurity (dig.watch)ISO27090 Approaches Formal Publication — stage 60.00 (LinkedIn)
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →