RSS Amplifier

AI regulation, standards and reality · May 8, 2026

prEN 18282 heads to Enquiry: Cybersecurity specifications for AI Systems

0
Sign in to vote or save

Adam Leon Smith DEng FBCS · AI regulation, standards and reality

prEN 18282 is now headed to JTC 21 Enquiry ballot. This is the harmonised standard that delivers presumption of conformity for the cybersecurity parts of Article 15 of the EU AI Act, the cybersecurity provision for high-risk AI systems.

The draft does something unusual for a cybersecurity standard. It does not include a control catalogue for you to select from. It contains an outcome framework you have to satisfy. If you are used to ISO/IEC 27001 and its Statement of Applicability, the difference matters.

prEN 18282 organises AI cybersecurity around five outcome categories: prevent, detect, respond, resolve, and control. The provider has to address each of these for every AI-specific attack type relevant to the system: data poisoning, model poisoning, adversarial attacks or model evasion, confidentiality attacks, and model flaws.

The structure is straightforward. Clause 6 identifies relevant circumstances. Clauses 7 and 8 identify vulnerabilities and threats. Clause 9 determines cybersecurity risks. Clause 10 selects measures across the five outcomes for each attack type. Clause 11 specifies testing. Clause 12 specifies documentation.

Annex ZA maps each subclause to Article 15. The mapping is granular. Every “measures to prevent / detect / respond to / resolve / control” element of Article 15 ties directly to a numbered subclause of Clause 10.

Read the original on adamleonsmith.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.