Cyber & IT Supervisory Forum - Additional Resources

A multilayer framework for good cybersecurity practices for AI June 2023

(9) How do you monitor if such requirements have been met? (M)

There were no answers relating to monitoring whether external AI solutions meet security requirements, however one MS mentioned that this is done by external companies.

(10) What are the means that you use to support SMEs/MEs to secure their AI products?

Aligned with the answers from question 3, under the topic of human labour, two MS provide guidance about AI security awareness, although used voluntarily, and the self-assessment mode regarding risks through the entire AI life cycle. Another MS related that, besides studies and white papers, there is also direct communication to discuss new trends and developments in the area. However, this MS does not provide any kind of classical consulting or assistance during development.

(11) Do you have/promote testing environments, like sandboxes/cyber ranges/simulation platforms to test and evaluate AI vulnerabilities before market? How?

Three MS mentioned the usage of sandboxes, cyber ranges and test platforms, where companies can test their solutions, however these solutions are of a general ICT nature and not AI-specific.

(12) Do you have specific measurements / key performance indicators (KPIs)/metrics that the AI stakeholders are required to use?

Nothing specific to AI was mentioned, with some MS mentioning the lack of experience on security issues related to AI, and others mentioning the expectation about the AI Act to provide guidance in this area.

(13) How do you inform the national stakeholders about the relevant legal instruments and standards available (e.g. regulatory sandboxes)?

Three MS reported having that information available and sharing it through channels such as white papers, websites and social media.

Conclusions As we can see in Figure 13, few MS mentioned having mechanisms concerning R & D, innovation and testing dedicated to AI security. We also found some expectations the MS that the AI Act will bring some light to this topic.

Figure 13 : Overview of AI-related ‘From the lab to the market’ answers

From the lab to the market

0 1 2 3 4 5 6

7 (M)

8 (M)

9 (M)

10.

11.

12.

13.

30

Made with FlippingBook Annual report maker