Definition
CAISO (Chief Artificial Intelligence Security Officer) is defined in this standard as a recommended horizontal AI security governance function responsible for oversight of AI security, AI risk, and AI accountability across the organisation.
CAISO is not a role title explicitly mandated by EU law. However, the underlying function is practically necessary to create a clear centre of responsibility for AI security.
Recommended Placement in the Governance Model
- CAISO should be positioned as a second-line governance function.
- It should remain independent from day-to-day product development.
- It should have the authority to stop or escalate unacceptable AI risk.
- It should have direct or functionally equivalent access to the highest governance level, such as the board, rector, vice-rector, or risk / digital governance committee.
- CAISO does not replace the CISO, DPO, CTO, or product owners; instead it connects their work from an AI security perspective, sets boundaries, and ensures decision traceability.
Mandate and Powers
The CAISO function shall have the authority to:
- approve or return AI security requirements for correction before significant AI deployments;
- require additional risk assessment, DPIA, AI ISA, red teaming, or security testing for sensitive or critical AI solutions;
- escalate "go / no-go" decisions to management where unacceptable AI security risk is identified;
- oversee the AI systems register, risk criteria, AI incident classification, and exception management;
- initiate or coordinate reviews of AI security policy, training, and monitoring metrics.
Core Responsibilities
- Manage AI security principles, control model, and methodologies.
- Define classification criteria for AI assets, AI registration, and AI risk assessment.
- Coordinate requirements for data security, model protection, prompt protection, RAG security, and inference security.
- Oversee AI supply-chain assessment: models, libraries, datasets, inference APIs, external providers.
- Coordinate AI incident management with CISO / SOC / CERT / DPO / legal.
- Ensure that AI solutions have an appropriate human oversight and escalation model.
- Oversee the AI literacy and AI security training programme.
- Prepare management reporting on AI security posture, exceptions, and critical risks.
Context Note
Horizontal placement is essential. Because the organisational context already includes an AI Competence Centre and technical AI environments such as Kubernetes, OpenStack, MLflow, Triton, Morpheus, and Jupyter, the CAISO function should not be narrowly embedded in a single project or single team. It should be implemented as a horizontal role spanning research, IT infrastructure, data protection, cybersecurity, and AI product/model ownership.