V1 – FAQ – MindMeister

FAQ

How do you accommodate accessibility?

We have a dedicated page that explains how we make this site more accessible.

Why have you performed this work?

The UK Government commissioned Copper Horse to map the AI security standards landscape and create a website that highlights the findings in a clear and accessible way. We aimed to map as many open standards, guidelines and recommendations as possible in order to find commonalities but also the differences or any outliers. The website’s findings have been displayed using a thematic analysis so that it can helpfully inform stakeholders, such as developers, operators and other governments.

How did you decide the mapping topics?

The 13 principles were taken from the European Telecommunications Standards Institute (ETSI), EN 304 223.

Will you develop the mapping further?

We plan to update the website regularly as and when applicable document become available. The space is constantly moving and as such, new and updated documentation is always emerging. We’ll keep tracking it as much as possible!

Why is the embedded mind map failing to load?

We are aware of an issue with the embedded MindMeister mind maps on certain browsers that restrict the functionality of embedded content. Currently the best alternative is to view the full screen mind map directly on MindMeister via the link provided above the mind map.

Standards and recommendations are constantly being updated. How up-to-date are these mappings?

Copper Horse’s study was completed in March 2026. We have therefore used the findings of this study to create the website, but we plan to update this site regularly based on newly published and submitted material.

Why didn’t you include x standard or recommendation?

Some documents were reviewed and judged to be out-of-scope. The reasons for this included that the document wasn’t publicly available, hadn’t been published at the time of review, did not include AI security requirements, had no specific recommendations, or that the specification was at too much of a specific low level to be practical as a reference. In some cases the standards were pay-to-view and as such we couldn’t access or map them.

Submissions of other documentation for future consideration are welcomed at: aisecuritymapping[@]copperhorse.co.uk.

Why didn’t you update to new version x of our recommendation?

We have observed in some cases, newer versions of recommendations have been issued but on review, the updates have been editorial in nature or are not related to AI security mapping work. For those recommendations, we’ve left the mapping at the version we mapped previously. We do however try to keep up-to-date where we can. Please contact us if you feel we’ve missed something.

Is there a downloadable copy of the data available?

Yes, all the data is available as open data on this site in JSON, CSV and ODS formats.

What platform was used to create the visual mappings?

We used MindMeister to provide the visual mappings.

How can I contact you?

Questions related to this site and its contents should be submitted to: aisecuritymapping[@]copperhorse.co.uk .

On the Reference Mapping, why are there some floating unconnected nodes?

Any organisations that only contained references to themselves in their document(s) and weren’t referenced by any other organisations (for example Qatar Central Bank) will have a single unconnected node.

Out-of-Scope Standards

The standards we’ve mapped against are all free to use, the following list of standards supplied by BSI, ISO and CEN/CENELEC are considered out-of-scope of this mapping exercise as they require the user to purchase a licence to use them.

  • ISO/IEC TR 6114
  • ISO/IEC 25456
  • ISO/IEC 25541
  • ISO/IEC TS 27115
  • ISO/IEC NP 7709
  • ISO/IEC 25959
  • ISO/IEC 42007
  • ISO/IEC 42119-7
  • ISO/IEC 42119-8
  • ISO/IEC 21617-2
  • ISO/IEC 21617-3

The following list of requirement have been partially mapped based on their contents which are available online for free:

  • ISO/IEC 42119-2
  • prEN 40000-1-1
  • prEN 40000-1-2
  • ISO/IEC 24970
  • ISO/IEC 27090
  • ISO/IEC 27091
  • ISO/IEC 5181
  • ISO/IEC TR 27563

search previous next tag category expand menu location phone mail time cart zoom edit close