Definition

CAISO (Chief Artificial Intelligence Security Officer) is defined in this standard as a recommended horizontal AI security governance function responsible for oversight of AI security, AI risk, and AI accountability across the organisation.

CAISO is not a role title explicitly mandated by EU law. However, the underlying function is practically necessary to create a clear centre of responsibility for AI security.

Recommended Placement in the Governance Model

  • CAISO should be positioned as a second-line governance function.
  • It should remain independent from day-to-day product development.
  • It should have the authority to stop or escalate unacceptable AI risk.
  • It should have direct or functionally equivalent access to the highest governance level, such as the board, rector, vice-rector, or risk / digital governance committee.
  • CAISO does not replace the CISO, DPO, CTO, or product owners; instead it connects their work from an AI security perspective, sets boundaries, and ensures decision traceability.

Mandate and Powers

The CAISO function shall have the authority to:

Core Responsibilities

Context Note

Horizontal placement is essential. Because the organisational context already includes an AI Competence Centre and technical AI environments such as Kubernetes, OpenStack, MLflow, Triton, Morpheus, and Jupyter, the CAISO function should not be narrowly embedded in a single project or single team. It should be implemented as a horizontal role spanning research, IT infrastructure, data protection, cybersecurity, and AI product/model ownership.