AI & Threat Landscape

ISO/IEC 27090 brings AI attacks into the 27000 family

If your organization runs an ISO 27001 program, ISO/IEC 27090 is the piece that finally speaks to the AI in your product. It is guidance for understanding, detecting, and mitigating the security threats that are specific to AI systems, and it extends the established 27000 controls rather than replacing them. It reached FDIS, the last stage before publication, in early 2026.

The threats it addresses are the ones an AI-enabled device actually faces: data poisoning, model theft and inversion, adversarial examples that fool the model at runtime, and privacy attacks that pull training data back out. These are the same failure modes the FDA listed for cyber devices, described here from the security engineer's side, with the detection and mitigation angle attached.

Why a medical team should care

Most device manufacturers already anchor their security program to ISO 27001. The gap has been that 27001 and 27002 were written for classic information systems, so an auditor could work through them without ever touching the model. ISO/IEC 27090 closes that gap. It tells you where your existing controls still hold and where AI needs something extra, so the model stops being the part of the product that nobody's framework covers.

THE STANDARDS LANDSCAPE FOR AI-ENABLED MEDICAL DEVICESIN DEVELOPMENTIEEE P63685BALLOTEDISO/IEC 27090IEC 63450PUBLISHEDAAMI CR515ISO/TS 24971-2IEC PAS 63621HARMONISEDnone
ISO/IEC 27090: balloted, the AI security guidance layered onto the ISO 27000 family.

Pair it with the FDA guidance and you get a clean division of labor. The FDA names the threats you must address in a submission. ISO/IEC 27090 gives you a recognized structure for the controls that address them. Neither is harmonized yet, and 27090 is guidance rather than a certifiable requirement, so treat it as the vocabulary and the checklist, not a stamp. The value is that when a reviewer asks how you handle model theft or poisoning, you can answer in a standard they recognize instead of improvising.

Get started

See your device through ELTON.

Start with one device. We build the twin from documentation your quality system already produces, run AI discovery remotely, and show you the graph: the handful to fix, and the evidence for everything else.

Exploitability management for medical devices. FDA §524B methodologyExploitability proven at runtime95% faster than legacy testing Book a Demo
Platform
OverviewAvoid FDA DeficienciesAvoid Consulting FeesDigital Twin TraceabilityAI MedDevice PentestingExploitability VerificationVulnerability ChainingRemediation OptimizationRemote TestLink™Incident ResponseAutomated VEX & MetricsCVSSv4 Migration
Solutions
EnterpriseStartups / SMBs Postmarket SurveillanceIncident ResponseSecurity EngineeringRegulatory AffairsFDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Japan MHLW
Why ELTON
One Solution Subscription TestingAI-NativeFDA ComplianceVerified ExploitabilityELTON vs. Legacy TestingThreat-Led AI PentestingMDDT MethodologyCredentialsDevice ModalitiesPricing
Resources
FDA Deficiency ListFDA Testing RequirementsFDA Cyber SOPs & TemplatesRemediation LibraryRegulatory GuidesWebinarsAI NewsletterThe End of Legacy TestingThe AI Vulnerability ExplosionSecurity AdvisoriesWhitepapersIntelligence & Blog
Company
AboutLeadershipCareersPartnershipsContact Meet ELTON