AI Governance and Security
We are bombarded with news that AI is dangerous and that nothing is being done to contain it. Whether AI is dangerous depends a lot on how it is used. However, the claim that nothing is being done to control it is incorrect.
Regarding the latter point, all organizations working with AI should analyze the risks and opportunities associated with its use. While the focus is most likely on opportunities, the risks tend to be overlooked.
Artificial intelligence is not new, but its widespread use is. When AI was the domain of only a few, its governance fell within management frameworks such as ISO/IEC 27001 (information security) and ISO/IEC 27701 (privacy protection). Within the EEA, the General Data Protection Regulation (GDPR) applies to the processing of personal data when AI tools are used.
The Law
Data protection principles are clear and independent of the specific information technology employed. According to regulation (EU) 2016/679 (General Data Protection Regulation or GDPR), the principles are:
Personal data shall be:
a) processed lawfully, fairly and in a transparent manner in relation to the data subject (‘lawfulness, fairness and transparency’);
b) collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, in accordance with Article 89(1), not be considered to be incompatible with the initial purposes (‘purpose limitation’);
c) adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (‘data minimisation’);
d) accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (‘accuracy’);
e) kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) subject to implementation of the appropriate technical and organisational measures required by this Regulation in order to safeguard the rights and freedoms of the data subject (‘storage limitation’);
f) processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’).
In addition, there are indirect references that differ from one country to another.
AI Act
EU Regulation 2024/1689 is commonly referred to as the AI Act. It entered into force within the EU on August 2, 2024; however, EU member states have until either December 2, 2027, or August 2, 2028, to transpose it into their national laws. Organizations in other countries that collaborate with EU entities and utilize artificial intelligence may need to ensure their compliance at the same time as their partners. Consequently, they cannot afford to wait; they must immediately begin adapting their operations to the AI Act.
ISO Standards
The ISO/IEC 27001 standard and the guidelines in ISO/IEC 27002 provide sound principles for software development, even if the level of detail may be limited. Organizations working with artificial intelligence that hold ISO 27001 certification must therefore adhere to the requirements stipulated by their certified system regarding software development, regardless of how the artificial intelligence is utilized. The fact that technology is classified as artificial intelligence is irrelevant in this context. Artificial intelligence is simply another tool in an organization's toolkit designed to ensure its progress and market competitiveness.
The ISO/IEC 42001 standard for artificial intelligence management systems was published in 2023. There is no obligation to consider or implement this standard. Its advantage lies in how well it aligns with the structure of ISO/IEC 27001, both the 2013 version and the latest 2022 edition, as well as ISO/IEC 27701:2025, the most recent version of that standard. Organizations are encouraged to consider integrating the requirements of ISO 42001 into their existing management systems.
As it happens, the author is a certified Lead Auditor for all these standards and is therefore well-versed in how they can be made to work together.
Other standards
ISO is not the only body developing standards or frameworks for AI usage. In the United States, NIST is widely looked to; the agency has released an AI Risk Management Framework (AI RMF). Since companies are under no legal obligation to implement this framework, they must do so on their own initiative. As with any risk management framework or standard, these serve as tools for organizations to manage risks within their operating environment. This is something all organizations should do as a matter of course, given the importance of identifying and addressing such risks for their operations.
In Europe, CEN, CENELEC, and ETSI are the bodies responsible for standardization in the context of EU regulations and are recognized as such by both the EU and EFTA. It is therefore wise to pay close attention to their activities.
The author is Icelandic and has been involved in work done by Standards Iceland. The organization closely monitors developments within the CEN-CENELEC cooperation platform and participates in the working group overseeing AI standardization. Several standards are currently being drafted, and one has already been published: EN 18286:2026 Artificial intelligence – Quality management system for EU AI Act regulatory purposes. Others under development include prEN 18282 (cybersecurity for AI systems), prEN 18284 (quality and management of AI datasets), and prEN 18285 (assessment framework), to name a few.
What is the recommended course of action?
As previously noted, it differs from one country to another which legal obligations organizations are currently faced with regarding AI usage. Various indirect legal obligations certainly exist; for instance, financial institutions must meet requirements of DORA—entailing the monitoring of their own systems and ensuring their critical partners are compliant—while legislation governing limited liability companies addresses the oversight responsibilities of boards of directors.
The work can be divided into several phases. The accompanying image illustrates this in seven phases. (The image was, of course, created with the help of AI; I first published it on my LinkedIn profile this spring, but it can also be found on the website secprico.com.)
For more information on the process, you can contact me at security@internet.is.
The process is detailed and ambitious, yet phases 1 through 5 can be followed without implementing a management system compliant with ISO/IEC 42001 (phase 6). However, organizations cannot avoid formulating a policy on AI usage that outlines objectives and approaches. It is necessary to understand the purpose of using AI, as well as where and how it is utilized. It is important to restrict organizational data accessible to AI and ensure that no data leaks occur. Asset tracking serves to monitor which tools are in use and to prevent "shadow AI" (i.e., unauthorized AI tools). Then there is risk assessment and risk treatment—arguably the most critical part of the process—though it certainly relies on the preceding steps having been completed. Finally, we want to monitor the activities being carried out.
The author is a consultant and a Lead Auditor for ISO 27001, ISO 27701, and ISO 42001.