Welcome to Protify.

In accordance with cookie legislation and our privacy policy, we only place strictly necessary functional cookies. 😊

For visitor analysis, we use Google Analytics (also cookieless). May we also place some Google Analytics analytical cookies to gain a better understanding?

Where AI Regulation and ISO 27001 Intersect

Written by Protify

The European AI Act aims to ensure that organizations handle artificial intelligence in a more regulated and responsible manner. For security officers and IT specialists, this is not a separate compliance exercise, but rather an extension of existing information security frameworks such as ISO 27001.

In practice, purely paper based regulations have long become insufficient. AI systems process data and make decisions on a daily basis. This introduces new risks that directly affect the confidentiality, integrity, and availability of information.

The EU AI Act vs ISO 27001

ISO 27001 is based on risk management. It starts by identifying and assessing risks. Appropriate control measures are then implemented for each risk. The AI Act is built on a similar logic, but with a specific focus on AI. The AI Act distinguishes several risk levels:

  • Unacceptable risk: prohibited applications
  • High risk: strict compliance requirements
  • Limited risk: transparency obligations
  • Minimal risk: limited regulation

Organizations that have implemented ISO 27001 at a high level of maturity already have a mature risk management process in place. This provides a strong foundation for compliance with the AI Act.

A Practican Example

A large European bank has not only implemented ISO 27001 as a certification framework, but has integrated it into its overall governance structure. Within the organization, the following measures have been established:

  • All information systems are included in a centralized risk register.
  • Risks are periodically assessed based on business impact.
  • Management has clearly defined risk appetite thresholds, indicating what level of risk the organization considers acceptable. This enables the assessment of whether AI applications fall within acceptable risk levels. If a specific AI application exceeds the defined risk appetite, additional controls are required.
  • All AI applications are assessed under the GDPR. This includes determining whether a Data Protection Impact Assessment (DPIA) is required when processing is likely to present a high privacy risk.
  • All AI use cases undergo a model risk assessment. Such an assessment evaluates not only IT security, but also questions such as: does the model produce explainable outcomes? Can the model unintentionally introduce bias? Does it make decisions based on incorrect assumptions? Can it generate inaccurate or uncontrollable outcomes? What is the impact if the model makes mistakes?

Through this mature approach, a direct connection is created between the AI Act and existing governance processes:

  • Risk classification of AI systems aligns with existing risk frameworks.
  • Documentation requirements under the AI Act can be incorporated into existing audit trails.
  • Monitoring and logging of AI systems can be integrated into existing security monitoring processes.
  • Governance roles such as risk owner and compliance officer can take on AI governance responsibilities without requiring entirely new organizational structures.

In summary: ISO 27001 maturity ensures that AI governance does not require a completely new system, but rather an extension of existing processes.Want to know more? Schedule a no obligation introductory meeting and together we will explore how we can support you.

Avatar photo

Protify

For more information, please follow us on LinkedIn

The Coffee Machine as an Information Security Tool

DialogueTrainer: An ISO 27001 Implementation