AI is becoming part of how organizations build products, serve customers, analyze data, and run everyday operations. But as AI adoption accelerates, security teams are facing a harder question:
How do you prove that the AI systems your organization develops, deploys, or relies on are secure?
That question is becoming particularly important for healthcare, financial services, technology, SaaS, and other organizations that operate in highly regulated or security-sensitive environments.
In 2026, HITRUST has expanded its focus on AI security and AI risk management, while continuing to evolve the HITRUST CSF through threat-informed updates. Its AI assurance program now includes dedicated AI Security Assessment and Certification and AI Risk Management Assessment offerings, while the HITRUST CSF continues incorporating emerging security and privacy sources.
For organizations using AI, the takeaway is straightforward:
AI security can no longer be treated as an extension of traditional cybersecurity alone. Organizations need to understand AI-specific threats, validate the controls protecting AI systems, and establish governance that can keep pace with changing AI risks.
Here’s what the 2026 HITRUST developments mean for organizations developing or deploying AI.
What Changed in HITRUST and AI Security in 2026?
HITRUST’s 2026 updates reflect a broader shift toward AI-specific security assurance and continuous, threat-informed risk management. Three developments are particularly important:
- HITRUST expanded its AI assurance offerings with dedicated AI Security and AI Risk Management assessments.
- HITRUST CSF v11.8.0 introduced new and refreshed authoritative-source mappings and continued consolidation of overlapping requirements.
- HITRUST’s Cyber Threat Adaptive program is increasingly incorporating AI-enabled attack techniques into its assurance approach.
Together, these developments signal a move away from treating AI as simply another technology asset. AI systems introduce additional security considerations involving models, prompts, training and inference data, agents, plugins, APIs, AI infrastructure, and the interactions between these components. HITRUST’s current AI assurance approach is designed to address those AI-specific considerations while building on established cybersecurity controls.
Why Does AI Security Need a Different Approach?
AI systems still depend on familiar technology. They run on infrastructure. They use applications, identities, networks, databases, APIs, and cloud services. That means traditional security controls remain important. But AI also introduces additional attack surfaces. For example:
- A generative AI application can expose sensitive information through inappropriate inputs or outputs.
- An AI model can be targeted through prompt injection.
- An AI application can connect to external tools or plugins.
- An AI agent can have permissions that allow it to perform actions on behalf of a user.
- AI models can be affected by data or model manipulation.
- AI applications can introduce dependencies that traditional application inventories may not fully capture.
HITRUST’s AI Security Certification specifically addresses AI security threats and includes areas such as AI threat identification, threat modeling, security evaluation, AI governance, roles and responsibilities, and AI-specific policies. The result is an important distinction:
Securing the infrastructure that runs AI is necessary, but it is not always sufficient to secure the AI system itself.
What Is HITRUST AI Security Certification?
HITRUST AI Security Certification is an assurance offering designed to help organizations demonstrate that they have addressed cybersecurity threats associated with deployed AI systems. According to HITRUST, the certification focuses specifically on the security of AI systems rather than attempting to cover every aspect of responsible AI.
The assessment can address generative AI, predictive AI, and rule-based AI systems. It considers AI-specific components such as the model, AI platform, and specialized AI computing infrastructure alongside the broader IT environment. Depending on how an assessment is tailored, the AI Security Certification can include up to 44 AI security-specific HITRUST CSF requirements. The certification can be:
- Conducted as a standalone AI Security Certification.
- Paired with a HITRUST e1 assessment.
- Paired with a HITRUST i1 assessment.
- Paired with a HITRUST r2 assessment.
When paired with an existing HITRUST assessment, organizations can address broader cybersecurity and AI security requirements within a connected assurance approach.
Who Is HITRUST AI Security Certification For?
This is an important distinction. HITRUST AI Security Certification is primarily designed for providers of AI systems, including AI application providers and AI platform providers. It is not intended for an organization simply using an AI system provided by another company. For example, an organization developing and operating its own AI platform may be a candidate for AI Security Certification.
An organization simply using a third-party AI application would instead need to consider how it evaluates that provider’s security and AI assurance. That distinction becomes especially important for third-party risk management. As more software vendors embed AI into their products, organizations can inherit AI risk through their existing vendor ecosystem. HITRUST has specifically highlighted AI vendors as an emerging third-party risk management challenge.
What AI Security Risks Does HITRUST Address?
AI security is broader than protecting an AI model from unauthorized access. HITRUST’s AI Security Certification addresses AI-specific threats, including areas such as:
- Prompt injection
- AI system threats
- Model-related security risks
- Data-related risks
- Excessive agency
- AI application security
- AI platform security
- AI infrastructure security
- AI threat modeling
- AI security testing
- AI governance and oversight
HITRUST identifies 13 AI security threats within its AI security threat register. Some are novel AI-specific threats, such as prompt injection, while others are established cybersecurity threats that can be amplified by AI deployments. This matters because traditional security assessments may not fully account for how AI changes the behavior and attack surface of an application.
What Is the Difference Between HITRUST AI Security and AI Risk Management?
This is one of the most important questions organizations should understand. HITRUST AI Security focuses on cybersecurity threats to AI systems. HITRUST AI Risk Management takes a broader view of AI-specific risks across the AI lifecycle.
HITRUST’s AI Risk Management Assessment is a non-certified assessment designed to help organizations identify, assess, and manage AI-specific risks. It uses 51 controls harmonized with NIST AI RMF and ISO/IEC 23894:2023 and incorporates guidance from the OWASP Top 10 for LLM Applications. The distinction can be simplified:
HITRUST AI Security
Focuses on:
“Are the AI systems protected against cybersecurity threats?”
HITRUST AI Risk Management
Focuses on:
“Have we identified and managed the broader risks associated with our AI systems?”
Organizations may need to address both. A company could have strong cybersecurity controls around an AI application while still having gaps in areas such as AI governance, risk assessment, accountability, or lifecycle management.
How Does HITRUST AI Security Work With the HITRUST CSF?
The AI Security approach builds on the HITRUST CSF rather than replacing it. HITRUST introduced a Security for AI Systems compliance factor that can be added to HITRUST e1, i1, and r2 assessments when an in-scope IT platform leverages an AI model. This is important because organizations generally do not have a completely separate technology environment for AI. An AI application may rely on:
- Cloud infrastructure
- Identity and access management
- Databases
- APIs
- Networks
- Applications
- Endpoint systems
- Security monitoring
Traditional security requirements remain relevant. AI-specific requirements add another layer for the unique threats and architectural characteristics introduced by AI.
This creates a more practical model:
Existing cybersecurity controls + AI-specific security controls = broader AI security assurance.
What Does HITRUST CSF v11.8.0 Mean for AI-Enabled Organizations?
HITRUST CSF v11.8.0 became available in May 2026. The release continued HITRUST’s effort to consolidate overlapping requirement statements and introduced or refreshed several authoritative-source mappings. Among the new mappings are:
- NIST SP 800-137
- ISO/IEC 29100:2024
- Commonwealth of Virginia SEC530
The release also updated third-party-related requirements. For AI-enabled organizations, the broader significance is less about one individual requirement and more about how HITRUST continues to evolve the CSF as the security landscape changes. Organizations should therefore avoid treating HITRUST as a static checklist. The framework is designed to evolve alongside emerging threats, technologies, and authoritative guidance.
Why Is Threat Intelligence Becoming More Important for HITRUST?
AI security is changing quickly. New attack techniques can emerge faster than traditional annual assessment cycles can respond. HITRUST’s Cyber Threat Adaptive program is designed to incorporate current threat intelligence into the HITRUST CSF and validated assessments. Its Q1 2026 analysis reviewed:
- 259 real-world breaches
- 4,761 threat intelligence articles
- 399,764 MITRE ATT&CK and MITRE ATLAS indicators
HITRUST reported that its AI Security Certification maintained more than 97% coverage of adversarial AI techniques observed during that period. The significance is not simply the percentage. The bigger takeaway is the move toward threat-adaptive assurance. AI security controls need to evolve as attackers discover new ways to exploit AI systems.
How Are Attackers Using AI in 2026?
AI is not necessarily creating an entirely separate category of cyberattacks. In many cases, it is making existing attacks faster, cheaper, and easier to scale. HITRUST’s Q2 2026 analysis noted that familiar techniques such as phishing, malicious packages, and social engineering remain prominent, while generative AI can increase the speed and scale of these attacks. For organizations deploying AI, this creates two related security problems:
- Protect the AI systems themselves.
- Protect the organization against attackers using AI to improve conventional attacks.
Both need to be considered as part of a broader cybersecurity strategy.
What Does This Mean for Healthcare Organizations?
Healthcare organizations have particularly strong reasons to pay attention to AI security. Healthcare providers, health technology companies, insurers, and healthcare SaaS vendors increasingly use AI for:
- Clinical workflows
- Documentation
- Patient communication
- Analytics
- Medical research
- Administrative automation
- Decision-support applications
- Customer service
- Data analysis
These systems may interact with highly sensitive information.
An AI system processing healthcare data therefore needs to be considered not only from an AI governance perspective but also from a cybersecurity, privacy, access-control, and third-party risk perspective.
For organizations already using HITRUST as part of their security assurance strategy, the AI Security approach provides a way to extend that assurance model to AI-specific threats. This is particularly relevant where AI systems interact with protected health information, sensitive research data, or other regulated information.
What About AI Vendors and Third-Party Risk?
AI does not only create risk inside your own environment.
It can enter through vendors.
A SaaS provider may add an AI assistant.
A cloud provider may introduce a new AI service.
A software vendor may integrate an external foundation model.
A business application may add an AI agent with access to customer data.
From the customer’s perspective, the AI system may appear to be part of an existing trusted vendor relationship.
That creates a new third-party risk question:
Do we understand the security controls protecting the AI capabilities embedded in the products and services we rely on?
HITRUST has identified AI vendors as an emerging third-party risk management challenge and is advocating for more continuous, independently validated assurance rather than relying solely on periodic vendor questionnaires or vendor claims. For security teams, this means AI vendor due diligence may need to become part of the broader third-party risk program.
Does HITRUST AI Security Replace ISO 42001?
No. HITRUST AI Security and ISO 42001 address different aspects of AI assurance.
HITRUST AI Security focuses specifically on cybersecurity threats associated with AI systems. ISO/IEC 42001 establishes an Artificial Intelligence Management System, covering broader organizational governance and management of AI.
The two can therefore be complementary.
For example: ISO 42001 can provide the management system and governance structure. HITRUST AI Security can provide a more focused approach to cybersecurity assurance for AI systems.
Organizations may also use frameworks such as NIST AI RMF and ISO/IEC 23894 to strengthen AI risk management. The right combination depends on the organization’s AI use cases, regulatory environment, customer requirements, risk profile, and assurance objectives.
Does HITRUST AI Security Replace NIST AI RMF?
No.
NIST AI RMF is a risk-management framework. HITRUST AI Security Certification provides an assessment and assurance model focused specifically on cybersecurity risks associated with AI systems. HITRUST’s AI Risk Management Assessment also maps 51 controls to NIST AI RMF and ISO/IEC 23894:2023, providing organizations with a way to connect AI risk management practices across these frameworks.
Organizations can therefore use NIST AI RMF as part of their AI risk-management strategy while using HITRUST assessments to obtain structured assurance around relevant controls.
What Should AI-Enabled Organizations Do Now?
The 2026 developments point to a practical set of next steps.
- Identify Where AI Is Being Used: Start by creating visibility into AI applications, models, platforms, APIs, agents, plugins, and third-party AI services. Do not limit the inventory to AI systems formally purchased by IT. AI may also exist inside existing applications and vendor platforms.
- Understand the AI Security Boundary: Identify:
- What model is being used?
- Where is it hosted?
- What data does it process?
- Which applications connect to it?
- Which identities can access it?
- What tools or plugins can it invoke?
- What external services does it communicate with?
The AI security boundary may extend beyond the model itself.
- Perform AI Threat Modeling: AI systems should be evaluated against AI-specific threats. HITRUST’s AI Security requirements specifically address identifying AI security threats and performing threat modeling before new models are deployed and periodically thereafter.
- Evaluate AI-Specific Controls: Review whether existing security controls adequately address AI-specific risks. This can include:
- Access controls
- Data protection
- Input and output filtering
- Logging
- Monitoring
- Model security
- API security
- AI application security
- Agent and plugin permissions
- Incident response
- Assess AI Risk Beyond Cybersecurity: AI security is only one component of responsible AI. Organizations should also consider:
- Privacy
- Transparency
- Accountability
- Bias and fairness
- Safety
- Explainability
- Regulatory obligations
HITRUST explicitly distinguishes its AI Security Certification from broader AI risks and provides its AI Risk Management Assessment for organizations seeking a broader risk-management perspective.
- Consider AI Security Assurance
If your organization develops or provides AI systems, determine whether HITRUST AI Security Certification aligns with your customer, regulatory, or assurance requirements. For organizations already pursuing HITRUST e1, i1, or r2, assess whether adding the AI security factor makes sense for in-scope AI systems.
How Can Organizations Prepare for a HITRUST AI Security Assessment?
Preparation should begin before evidence collection. A practical readiness process can include:
Step 1: Define the AI System Scope
Identify the AI applications, models, platforms, infrastructure, integrations, and supporting technology that fall within scope.
Step 2: Map AI Responsibilities
Determine who owns AI governance, security, risk management, model management, data protection, and incident response.
Step 3: Identify AI-Specific Threats
Document relevant threats and establish an AI threat register.
Step 4: Perform Threat Modeling
Evaluate how the AI system could be attacked and which countermeasures are currently in place.
Step 5: Review Policies
Ensure existing security, data governance, software development, risk management, incident management, business continuity, and disaster recovery policies address AI-specific considerations where appropriate.
Step 6: Validate Controls
Do not rely solely on documented policies. Determine whether controls actually work in the deployed AI environment.
Step 7: Collect Evidence
Establish evidence that demonstrates how controls operate and how AI risks are being managed.
Step 8: Remediate Gaps
Prioritize and address gaps before the formal assessment. This approach helps organizations move from AI adoption to AI assurance.
Why AI Security Needs Continuous Attention
One of the biggest mistakes organizations can make is treating AI security as a one-time certification project.
AI environments change quickly.
A model can be replaced.
A new agent can be introduced.
A plugin can gain additional permissions.
A vendor can add an AI capability to an existing product.
A new vulnerability can emerge.
An attacker can develop a new technique.
That means an AI security program needs to evolve alongside the AI environment.
HITRUST’s threat-adaptive approach reflects this broader shift toward assurance that incorporates current threat intelligence rather than relying solely on static control sets.
For organizations, the objective should be continuous confidence:
Know what AI you have.
Know what it can access.
Know what can go wrong.
Know which controls protect it.
Test whether those controls work.
Keep the assurance current.
How Accorian Helps Organizations Prepare for AI Security and HITRUST
AI security requires more than implementing a framework. Organizations need to understand their AI environment, identify risks, evaluate controls, and maintain evidence as that environment changes. Accorian brings together AI security, cybersecurity, compliance, and risk management expertise to help organizations navigate this evolving landscape. Its approach can support organizations with:
- AI security assessments
- AI risk assessments
- AI threat modeling
- AI governance
- HITRUST readiness
- HITRUST CSF assessments
- AI-specific control implementation
- Gap assessments
- Evidence preparation
- Remediation
- Multi-framework compliance
Accorian also uses GORICO, its AI-enabled GRC platform, to help organizations streamline compliance, evidence management, risk workflows, policy review, and control tracking across multiple frameworks. This matters because AI governance rarely exists in isolation.
An organization may need to manage HITRUST, HIPAA, ISO 27001, ISO 42001, SOC 2, NIST, PCI DSS, and other requirements at the same time. A connected approach can help organizations identify overlapping requirements, reduce duplicate effort, and maintain greater visibility into their compliance posture.
What Do the 2026 HITRUST Updates Mean for AI-Enabled Organizations?
The biggest change is not a single new control. It is the growing recognition that AI requires dedicated security assurance. HITRUST’s 2026 developments show that AI security is becoming more structured, threat-informed, and integrated with broader cybersecurity assurance. Organizations developing or deploying AI should be prepared to answer:
- Where is AI being used?
- What AI systems are in scope?
- What data does each system process?
- What identities and permissions can access it?
- What AI-specific threats apply?
- How are those threats being modeled and managed?
- Which security controls protect the AI system?
- Have those controls been tested?
- How is AI risk being monitored over time?
- How are third-party AI providers being evaluated?
The organizations that can answer these questions with evidence will be better positioned to demonstrate trust in their AI systems.
AI adoption is moving quickly. AI security assurance needs to keep pace.
For organizations already using HITRUST, the opportunity is to extend an established cybersecurity assurance foundation into the AI environment rather than treating AI security as a completely separate program. And for organizations just beginning their AI governance journey, 2026 is a good time to move beyond AI policies and start building measurable, evidence-based AI security.
Frequently Asked Questions About HITRUST and AI Security
1. What is HITRUST AI Security Certification?
HITRUST AI Security Certification is an assurance offering focused on cybersecurity threats associated with deployed AI systems. It can address generative, predictive, and rule-based AI and can be offered standalone or paired with HITRUST e1, i1, or r2 assessments.
2. How many controls are included in HITRUST AI Security Certification?
The assessment can include up to 44 AI security-specific HITRUST CSF requirements, depending on how the assessment is tailored. These requirements are added to an underlying HITRUST assessment rather than assessed completely independently.
3. What AI systems can be assessed by HITRUST?
HITRUST’s AI Security Certification can apply to generative AI, predictive AI, and rule-based AI systems. It considers AI-specific components such as models, AI platforms, and specialized AI computing infrastructure alongside the broader IT environment.
4. What is the difference between HITRUST AI Security and HITRUST AI Risk Management?
HITRUST AI Security focuses on cybersecurity threats to AI systems. HITRUST AI Risk Management takes a broader view of AI-specific risks across the AI lifecycle and uses 51 controls mapped to NIST AI RMF and ISO/IEC 23894:2023.
5. Is HITRUST AI Security Certification the same as ISO 42001?
No. HITRUST AI Security Certification focuses on cybersecurity assurance for AI systems, while ISO 42001 establishes an Artificial Intelligence Management System. Organizations can use the two approaches together depending on their assurance and governance requirements.
6. Does HITRUST AI Security apply to organizations that only use AI?
HITRUST states that its AI Security Certification is designed for providers of AI systems, including AI application and AI platform providers. Organizations that simply use third-party AI systems should instead evaluate the security assurance provided by those AI vendors and consider their own AI governance and risk-management requirements.
7. Does HITRUST CSF include AI security requirements?
Yes. HITRUST has incorporated AI-specific security requirements into its CSF and provides a Security for AI Systems compliance factor that can be added to applicable e1, i1, and r2 assessments.
8. What changed in HITRUST CSF v11.8.0?
HITRUST CSF v11.8.0, released in May 2026, continued requirement-statement consolidation and introduced or refreshed authoritative-source mappings, including NIST SP 800-137 and ISO/IEC 29100:2024.
9. Why is HITRUST focusing more on AI security?
AI introduces new security considerations while also accelerating existing attack techniques. HITRUST’s 2026 Cyber Threat Adaptive analysis found continued growth in AI-enabled attack activity and emphasized the need for assurance that evolves with the threat landscape.
10. How should organizations prepare for HITRUST AI Security Certification?
Organizations should define their AI system scope, identify AI-specific threats, perform threat modeling, establish AI governance responsibilities, update relevant policies, validate AI security controls, collect evidence, and remediate identified gaps before the formal assessment.
11. How does HITRUST help with AI third-party risk?
HITRUST’s AI assurance approach can help organizations evaluate security assurance for AI systems and AI providers. This is increasingly relevant as vendors embed AI into existing products and services, creating AI risk across the third-party ecosystem.
Key Takeaway
HITRUST’s 2026 AI security developments signal a shift from treating AI as another technology asset to treating AI security as a distinct assurance requirement.
For AI-enabled organizations, the priority is not simply adopting AI safely. It is being able to demonstrate, with evidence, that AI-specific risks have been identified, controls have been implemented, and those controls continue to work as the AI environment evolves.
CONTACT US


