Cybersecurity and Artificial Intelligence

The revised European Union (EU) product liability directive extends the definition of product (to include software) and defectiveness (with respect to cybersecurity requirements). The EU cybersecurity regulation moves further on with a specific focus on products with digital elements (EU Cyber Resilience Act), while the EU Artificial Intelligence (AI) Act marks an historic milestone in the quest to regulate disruptive emerging technologies. The convergence of such important changes in the EU legislative framework emphasizes the importance of the intersection among product liability, cybersecurity and AI. Moreover, cybersecurity and AI have a multifaceted relationship where AI does not only emphasize already well-known cybersecurity risks, but it also introduces peculiar cybersecurity issues. As more products with digital elements rely on Machine Learning (ML), a spotlight is thrown on ML cybersecurity vulnerabilities with a prominent role played by attacks targeting a core ML process: learning from data. The analysis of attacks peculiar to ML suggests to carefully review the defensive strategies in place. Given the central role that data play in the learning process, such defensive strategies should be crafted considering data governance and protection as cornerstones and implemented leveraging a mix of frameworks, policies, and techniques aimed to effectively manage, also from a product liability perspective, the specific cybersecurity risks implied by the adoption of ML.

Paper

The full text of this publication is not hosted on 44B due to licensing.

Read it at OpenAlex

Similar papers

© 2026 NYSGPT2525 LLC