Cybersecurity certification of Artificial Intelligence: a missed opportunity to coordinate between the Artificial Intelligence Act and the Cybersecurity Act

Federica Casarosa
DOI: https://doi.org/10.1365/s43439-021-00043-6
2022-01-05
International Cybersecurity Law Review
Abstract:In April 2021, the Commission published a draft proposal for a regulation on artificial intelligence (AI) systems aimed at striking a balance between the market need for a competitive and dynamic ecosystem and the need to minimise risks to the safety and fundamental rights of users and citizens. Among the set of obligations that apply to high-risk AI technologies, the AI Act includes a specific provision addressing the security and robustness of AI systems. This provision overlaps with existing legislation addressing cybersecurity, namely the certification process defined in Regulation 2019/881 on the European Union Agency for Cybersecurity and on information and communication technology cybersecurity certification. Although the AI Act hints at a possible path towards mutual recognition of certifications, a deeper analysis of the provisions and a comparison between the underlying features of the certification mechanisms show that the different approaches adopted in the two acts may undermine the goal of certification mechanisms as trust-enhancing and transparency instruments. As a result, this paper provides evidence of the missed opportunity for the AIA proposal to link and coordinate in a more structured way with the cybersecurity framework.
What problem does this paper attempt to address?