ISO/IEC 27090 and 27091 give enterprises practical direction for securing artificial intelligence and protecting personal data across the AI lifecycle. Together, the draft standards address risks that conventional application security may miss, from poisoned training data and model theft to privacy leakage during inference.
For CISOs, technology leaders, and compliance teams, the business case is clear: protect intellectual property, prevent data exposure, maintain reliable AI-enabled services, and produce evidence that supports ISO 27001, GDPR, and EU AI Act governance.
Why ISO/IEC 27090 and 27091 matter
ISO/IEC FDIS 27090 focuses on AI-specific security threats, their consequences, detection, and mitigation throughout the system lifecycle. ISO/IEC DIS 27091 focuses on identifying, evaluating, and treating privacy risks in AI systems and machine-learning models.
The drafts are complementary. Security controls can stop unauthorized access yet still permit excessive data collection or harmful inference. Privacy controls can minimize data yet fail if an attacker poisons a model, extracts sensitive outputs, or exploits an enterprise connector.
Key components of ISO/IEC 27090 and 27091
Training data and model integrity
Organizations should verify data provenance, access, quality, and permitted use. Threat models must cover poisoning, malicious fine-tuning, compromised model artifacts, dependency risk, and theft of proprietary datasets or model weights.
Secure inference and application integration
Runtime controls should address adversarial inputs, prompt injection, model extraction, membership inference, sensitive information disclosure, excessive agency, denial of service, and unsafe output handling. RAG pipelines, agents, APIs, plugins, and corporate applications need least-privilege access, secrets protection, input controls, and output validation.
Privacy engineering and impact assessment
Teams should map personal data from collection to deletion, including prompts, embeddings, logs, outputs, and inferred attributes. Apply data minimization, purpose limitation, retention controls, de-identification, data subject rights, and a DPIA where processing is likely to create high risk.
How to implement ISO/IEC 27090 and 27091
1. Inventory AI systems and data flows
Record each use case, owner, model, provider, data source, integration, user group, decision impact, and deployment environment. Include shadow AI and third-party features embedded in SaaS platforms.
2. Run combined security and privacy assessments
Threat-model the full lifecycle: design, data preparation, training, testing, deployment, inference, monitoring, retraining, and retirement. Use the OWASP Top 10 for LLMs and GenAI Apps and NIST AI RMF as complementary references. Link abuse cases and privacy harms to business impact, control owners, residual risk, and acceptance decisions.
3. Implement controls and retain evidence
Use IAM, PAM, MFA, encryption, segmentation, DLP, secure pipelines, model and dataset versioning, logging, red teaming, continuous monitoring, and incident response. Retain approvals, test results, vendor assurance, exceptions, and remediation records.
Common challenges and considerations
Common obstacles include unclear ownership, changing models, opaque providers, insufficient telemetry, unapproved AI use, and tension between model utility and privacy. As of June 2026, both documents remain under development and provide guidance rather than standalone certification schemes. Maintain a versioned control baseline and review it when final texts are published.
Best practices
- Assign accountable owners across security, privacy, legal, data, engineering, and business teams.
- Apply risk tiers so high-impact use cases receive stronger testing, oversight, and approval.
- Test controls against realistic abuse cases before deployment and after material changes.
- Monitor models, data, integrations, and suppliers continuously rather than relying on a one-time review.
Conclusion
ISO/IEC 27090 and 27091 can help enterprises turn AI assurance into an operational discipline. Start with visibility, assess security and privacy together, prioritize high-impact systems, and build traceable controls into delivery pipelines. This reduces incident exposure while strengthening customer trust and regulatory readiness.
At B2BCyber, we support organizations with cybersecurity, compliance, governance, risk management, cloud security, security architecture, IAM/PAM, and regulatory readiness. If you need delivery support, explore our Security and Compliance Project Delivery. If you need to add cybersecurity skills quickly, see our Cybersecurity Experts on Demand model.
Compliance Checklist
- Maintain an approved inventory of AI systems, models, data, integrations, and owners.
- Document lifecycle threat models and privacy impact assessments for prioritized use cases.
- Enforce least privilege, data minimization, retention, logging, and secure change control.
- Validate providers, datasets, models, plugins, and APIs before use and throughout the supplier relationship.
- Record testing, incidents, exceptions, residual risks, approvals, and remediation evidence.

