Ukraine: cybersecurity of AI systems
On 11 March 2026 the Cabinet's portal reported that the State Service of Special Communications and Information Protection had approved voluntary recommendations on the cyber protection of information and communication systems that use AI; the order is, per the notice, dated 23 February 2026, no. 154.
Why it matters
Ukraine now has an official list of threats specific to AI systems and of measures against them, not only a general security requirement. An editorial assessment: the document is voluntary, a guide rather than a norm carrying liability.
What the notice names. The order was issued to carry out the action plan of the Concept of AI Development in Ukraine for 2025-2026. Five groups of threats: attacks on AI supply chains, poisoning of data and models, adversarial attacks, prompt injection, model inversion and theft. Measures: adversarial training, federated learning, differential privacy, filtering of inputs, anomaly monitoring, data quality. AI risk management is to be built into the organisation's general cybersecurity system using ISO/IEC 23894:2023, ISO/IEC 42001:2023 and NIST frameworks. What the record does not claim. The order and the recommendations themselves were not read: cip.gov.ua gave no response to curl, 403 to WebFetch and did not open in the pane, so all of the above comes from the Cabinet portal's notice, which relays the content. The recommendations are voluntary; the notice does not say how many bodies have applied them.