Navigation and service

Criteria Catalogue for AI Cloud Services – AIC4

The Criteria Catalogue for AI Cloud Services (AIC4) specifies minimum requirements for the secure use of machine learning methods in cloud services. It is intended as an extension of the C5 (Cloud Computing Compliance Criteria Catalogue). Its objective is to clearly set out the information security level achieved by an AI cloud service based on a standardised audit. Cloud customers can then use this security assessment as part of their own risk analysis. Cloud providers, auditors and cloud customers use the criteria catalogue (AIC4). Each of these parties has a duty to cooperate when it comes to information security.

The C5 catalogue formulates general minimum requirements for secure cloud computing that are relevant for every cloud service. The AIC4 criteria catalogue, meanwhile, includes additional special criteria that are also relevant if machine learning methods are used. AIC4 criteria address the areas of security and robustness, performance and functionality, reliability, data quality, data management, explainability and bias. They cover the entire lifecycle of AI services – that is, development, testing, validation and operation.

AI Cloud Service Compliance Criteria Catalogue (AIC4)

Contact

If you have questions about the AIC4 that are not addressed by the FAQs below, please contact us at
aicloudsecurity@bsi.bund.de
We also appreciate feedback on the content of the catalogue and its applicability.

FAQs

Applications

Role of the BSI

Differences in scope

Further development

Substance of the AIC4 criteria