If your organization runs an ISO 27001 program, ISO/IEC 27090 is the piece that finally speaks to the AI in your product. It is guidance for understanding, detecting, and mitigating the security threats that are specific to AI systems, and it extends the established 27000 controls rather than replacing them. It reached FDIS, the last stage before publication, in early 2026.
The threats it addresses are the ones an AI-enabled device actually faces: data poisoning, model theft and inversion, adversarial examples that fool the model at runtime, and privacy attacks that pull training data back out. These are the same failure modes the FDA listed for cyber devices, described here from the security engineer's side, with the detection and mitigation angle attached.
Most device manufacturers already anchor their security program to ISO 27001. The gap has been that 27001 and 27002 were written for classic information systems, so an auditor could work through them without ever touching the model. ISO/IEC 27090 closes that gap. It tells you where your existing controls still hold and where AI needs something extra, so the model stops being the part of the product that nobody's framework covers.
Pair it with the FDA guidance and you get a clean division of labor. The FDA names the threats you must address in a submission. ISO/IEC 27090 gives you a recognized structure for the controls that address them. Neither is harmonized yet, and 27090 is guidance rather than a certifiable requirement, so treat it as the vocabulary and the checklist, not a stamp. The value is that when a reviewer asks how you handle model theft or poisoning, you can answer in a standard they recognize instead of improvising.
Start with one device. We build the twin from documentation your quality system already produces, run AI discovery remotely, and show you the graph: the handful to fix, and the evidence for everything else.