The present document defines baseline security requirements for AI models and systems. The present document includes in its scope systems that incorporate deep neural networks, such as generative AI. For consistency, the term "AI systems" is used throughout the present document when framing the scope of provisions and the term "AI security", which is considered a subset of cybersecurity, is used when addressing any cybersecurity issues in the scope of the provisions. The present document is not designed for academics who are creating and testing AI systems only for research purposes (AI systems which are not going to be deployed).
PUBLISHED
SRPS ETSI EN 304 223 V2.1.1:2026
60.60
Standard published
Mar 31, 2026