ISO 27001 was built around servers, applications, and endpoints — not prompt injection, model abuse, or retrieval leakage. Enterprise customers and auditors increasingly ask whether your AI systems are actually covered. Here's how to extend an existing ISMS to genuinely cover them.
Most enterprise AI systems that process regulated or sensitive data should be included in ISMS scope — AI SaaS platforms, customer support AI, enterprise copilots, legal AI assistants, RAG systems, and AI-powered APIs all qualify. Organizations cannot secure what they haven't inventoried, so AI asset visibility is the foundational step that everything else depends on.
Asset management gets significantly more complex once AI enters the picture. Four categories now need explicit tracking:
Foundation models, fine-tuned models, local inference models.
Datasets, embeddings, vector stores.
Inference APIs, orchestration frameworks, vector databases.
Prompts, retrieval systems, autonomous workflows, plugins.
Traditional ISMS programs focus on malware, unauthorized access, and network intrusion. AI introduces risks that don't map cleanly onto that model:
Exposure of personal data, confidential data, or regulated information through retrieval, logging, or model output.
AI failures impacting services, decision-making, or automation pipelines.
Violations involving GDPR, the EU AI Act, HIPAA, or SOC2 obligations.
Unsafe AI behavior damaging customer trust and brand credibility.
The HexTyx AI Security Assessment maps directly to ISO 27001 control areas: asset inventory, access control, and runtime governance.
The largest shift for 2026 ISMS programs is that security has to continue after deployment, not just validate before it. Traditional security focused heavily on pre-deployment review; AI systems require continuous runtime monitoring across four areas: prompt activity (injection attempts, jailbreaks), retrieval behavior (unauthorized document access, cross-tenant leakage), AI outputs (hallucinations, policy violations), and autonomous actions (unauthorized execution, privilege escalation).
RAG systems specifically need retrieval-aware authorization, classification-aware retrieval, vector database monitoring, tenant isolation, and retrieval audit logging layered on top of standard ISMS access control — the retrieval engine is a new access surface that traditional controls weren't designed to cover.
| ISO 27001 Area | AI-Specific Control |
|---|---|
| Asset Management | AI inventory, model registry |
| Access Control | Retrieval-aware permissions |
| Logging | Prompt and inference telemetry |
| Risk Management | AI threat modeling |
| Vendor Security | AI provider due diligence |
| Incident Response | AI runtime containment |
| Monitoring | AI observability systems |
| Business Continuity | Model redundancy planning |
Auditors increasingly ask how prompts are logged, how AI misuse is detected, how models get approved before deployment, how AI vendors are assessed, how retrieval leakage is prevented, how AI incidents are handled, and how autonomous agents are governed. These are reasonable extensions of existing ISMS audit questions — they just didn't have AI-specific answers until recently.