option
Home
News
Navigating the New ETSI AI Security Standard

Navigating the New ETSI AI Security Standard

June 7, 2026
79

ETSI EN 304 223 establishes foundational security requirements for artificial intelligence that organizations should embed within their governance structures.

As enterprises integrate machine learning into core workflows, this European Standard provides specific provisions for protecting AI models and systems. It is the first globally applicable European Standard for AI cybersecurity, formally approved by National Standards Organizations, which reinforces its credibility across international markets.

Serving as a complementary benchmark to the EU AI Act, this standard acknowledges that AI systems carry unique risks—including data poisoning, model obfuscation, and indirect prompt injection—which conventional software security practices frequently overlook. It applies to deep neural networks, generative AI, and basic predictive systems, explicitly excluding only those used exclusively for academic research.

ETSI standard defines the chain of accountability for AI security

One persistent challenge in enterprise AI deployment is assigning risk ownership. The ETSI standard addresses this by delineating three core technical roles: Developers, System Operators, and Data Custodians.

In many organizations, these boundaries become unclear. For example, a financial services company that fine-tunes an open-source model for fraud detection qualifies as both a Developer and a System Operator. This dual role imposes strict responsibilities: the firm must secure the deployment environment while documenting training data provenance and model design audits.

The explicit inclusion of "Data Custodians" as a separate stakeholder group directly affects Chief Data and Analytics Officers (CDAOs). These individuals manage data permissions and integrity—a role now carrying clear security obligations. Custodians must verify that the system's intended use matches the sensitivity of its training data, effectively embedding a security gatekeeper within data management processes.

The ETSI AI standard emphasizes that security must not be an afterthought added only during deployment. In the design phase, organizations must perform threat modeling that accounts for AI-specific attacks, such as membership inference and model obfuscation.

One requirement mandates that developers limit functionality to minimize the attack surface. For example, if a system employs a multimodal model but only processes text, the unused modalities—such as image or audio processing—become risks that need mitigation. This pushes technical leaders to rethink the common habit of deploying large, general-purpose foundation models when a smaller, more specialized model would be sufficient.

The standard also mandates rigorous asset management. Developers and System Operators must keep a detailed inventory of assets, covering interdependencies and connectivity. This facilitates discovery of shadow AI—IT leaders cannot protect models they are unaware of. Additionally, the standard requires disaster recovery plans specifically designed for AI attacks, ensuring that a "known good state" can be restored if a model is compromised.

Supply chain security poses a direct challenge for organizations that depend on third-party vendors or open-source repositories. Under the ETSI standard, if a System Operator opts to use poorly documented AI models or components, they must justify that choice and document the accompanying security risks.

In practice, procurement teams can no longer accept "black box" solutions. Developers must supply cryptographic hashes for model components to verify their authenticity. When training data is obtained from public sources—common for large language models—developers must record the source URL and acquisition timestamp. This audit trail supports post-incident investigations, especially when determining whether a model was affected by data poisoning during training.

Enterprises that provide APIs to external customers must implement controls to counter AI-specific attacks, such as rate limiting to prevent adversaries from reverse-engineering the model or overwhelming defenses to inject poisoned data.

This lifecycle approach continues into the maintenance phase, where the standard views major updates—like retraining on new data—as deploying a new version. Under the ETSI AI standard, such updates require fresh security testing and evaluation.

Continuous monitoring is also systematized. System Operators must analyze logs not only for uptime but also to identify "data drift" or gradual behavioral changes that might signal a security breach. This shifts AI monitoring from a performance metric to a security function.

The standard also covers the "End of Life" phase. When a model is retired or transferred, organizations must engage Data Custodians to ensure secure disposal of data and configuration details. This requirement prevents sensitive intellectual property or training data from leaking through discarded hardware or forgotten cloud instances.

Executive oversight and governance responsibilities

Complying with ETSI EN 304 223 requires revisiting current cybersecurity training programs. The standard demands role-specific training, ensuring that developers grasp secure coding for AI while general employees stay alert to threats like social engineering through AI outputs.

"ETSI EN 304 223 marks a significant milestone in creating a shared, robust foundation for AI system security," said Scott Cadzow, Chair of ETSI's Technical Committee for Securing Artificial Intelligence.

"As AI becomes more embedded in critical services and infrastructure, the value of clear, practical guidance that acknowledges both the complexity of these technologies and the realities of deployment cannot be overstated. The effort behind this framework stems from broad collaboration, enabling organizations to trust AI systems that are resilient, trustworthy, and secure by design."

Adopting the baselines outlined in the ETSI AI security standard creates a framework for safer innovation. Through documented audit trails, well-defined roles, and supply chain transparency, organizations can reduce the risks of AI adoption while building a defensible stance for future regulatory reviews.

A forthcoming Technical Report (ETSI TR 104 159) will apply these principles specifically to generative AI, addressing challenges such as deepfakes and disinformation.

Also read: Allister Frost on tackling workforce anxiety for successful AI integration

Interested in insights from AI and big data experts? Explore the AI & Big Data Expo in Amsterdam, California, and London. This comprehensive event, part of TechEx, is co-located with other leading technology conferences. Click here for details.

AI News is brought to you by TechForge Media. Discover other upcoming enterprise technology events and webinars here.

Related article
Swedish AI Startup Lovable Eyes $13.2 Billion Valuation After Major Funding Round Swedish AI Startup Lovable Eyes $13.2 Billion Valuation After Major Funding Round As AI-driven coding tools gain traction, Swedish startup Lovable has secured a major funding round. The company aims to raise $3 billion, potentially boosting its valuation to $13.2 billion—double the $6.6 billion recorded last December. Menlo Ventur
Google Tests Remy AI Agent for Gemini as Focus Shifts to User Control Google Tests Remy AI Agent for Gemini as Focus Shifts to User Control According to Business Insider, Google is testing Remy, a new AI personal agent for Gemini. This tool aims to execute tasks on behalf of users, streamlining both professional workflows and daily routines.Currently, Remy is undergoing testing in an int
How to fix Core Web Vitals for better SEO rankings How to fix Core Web Vitals for better SEO rankings Streamline Report Card Comments with AI ToolsIntroductionAI Tools for Generating Report Card CommentsMagic SchoolAlmanac AIChat GPTUsing Magic School to Generate Report Card CommentsLogging into Magic SchoolSelecting the Report Card Comments ToolCust
Related Special Topic Recommendations
writing Best AI Outline Generators for Long-Form SEO Articles
Best AI Outline Generators for Long-Form SEO Articles

2026 Latest Best Top-Rated AI Outline Generators for Long-Form SEO Articles, meticulously curated by XIX.AI. These powerful tools offer game-changing assistance in creating high-quality content quickly, boosting writing efficiency significantly. Get a free vs paid comparison along with real-world tests and detailed rankings to help you find the must-try option that suits your needs. Explore now to unlock your AI edge.

8 tools
xix.ai
Education and Learning AI Study Tools for Homework and Exam Prep
AI Study Tools for Homework and Exam Prep

2026 Latest Best AI Study Tools for Homework and Exam Prep! XIX.AI curates a top-rated list of powerful, game-changing tools that help students boost productivity, streamline homework completion, and ace exams through real-world tests. Get a free vs paid comparison, detailed rankings, and must-try options to unlock your AI edge. Explore now!

10 tools
xix.ai
Music composition AI Vocal Demo Tools for Songwriters, Hooks, Toplines, and Multilingual Draft Sessions
AI Vocal Demo Tools for Songwriters, Hooks, Toplines, and Multilingual Draft Sessions

2026 Latest Best AI Vocal Demo Tools for Songwriters, Hook Creators, and Multi-Language Content Teams! XIX.AI has curated a top-rated list of powerful game-changing tools that go through rigorous real-world tests. You’ll find detailed free vs paid comparison data, comprehensive rankings, and must-try options to help you boost writing efficiency and unlock your creative potential. Explore now to discover your perfect tool for all your content needs!

9 tools
xix.ai
Business Best AI Competitive Research Tools for Small Businesses
Best AI Competitive Research Tools for Small Businesses

2026 Latest Best Top-rated AI Competitive Research Tools for Small Businesses! XIX.AI has curated a highly powerful game-changing collection, updated weekly with rigorous real-world tests and detailed rankings. You can find a comprehensive free vs paid comparison to help you identify the must-try tools that boost your productivity and give you a competitive edge. Explore now to discover your perfect tool!

9 tools
xix.ai
Image editing Photoshop AI Retouch Tools for Ecommerce Apparel, Skin Cleanup, and Color Consistency
Photoshop AI Retouch Tools for Ecommerce Apparel, Skin Cleanup, and Color Consistency

2026 Latest Best Photoshop AI retouch tools for ecommerce apparel, skin cleanup, and color consistency! This top-rated curated list features powerful game-changing solutions that help you boost writing efficiency, streamline content creation, and achieve perfect visual results effortlessly. Each tool has undergone real-world tests through weekly updated rankings, complete with free vs paid comparison details. Backed by XIX.AI, it’s the must-try guide for anyone aiming to unlock your AI edge. Explore now!

10 tools
xix.ai
Prompt Best AI Prompt Libraries for ChatGPT Workflows
Best AI Prompt Libraries for ChatGPT Workflows

2026 Latest Best Top-Rated AI Prompt Libraries for optimizing all types of ChatGPT workflows. XIX.AI has curated a powerful, game-changing collection that goes through rigorous real-world tests to ensure top performance. You can find detailed free vs paid comparisons and expert rankings to help you choose the must-try tools that boost your productivity and unlock your AI edge. Explore now!

11 tools
xix.ai
Comments (0)
0/500
OR