ISC2 updates its AI exam guidance and maps AI topics to all eight CISSP domains
ISC2 published an updated Exam Guidance for Artificial Intelligence on September 1, 2026. The CISSP section shows where AI security sits in the current outline, which has been in effect since April 15, 2024.
What was published
On September 1, 2026, ISC2 released an updated version of its Exam Guidance for Artificial Intelligence. It builds on the first version, released in April 2026.
The guide shows how AI topics are built into all nine ISC2 certification exams. ISC2 says it maps AI-related content across more than 50 domains and 200 tasks. The main addition is a detailed section on Certified in Cybersecurity (CC), whose new outline took effect on September 1, 2026.
What it says about CISSP
The CISSP section is based on the CISSP Exam Outline effective April 15, 2024. ISC2 says it weaves AI security tasks into all eight domains instead of treating AI as a separate topic.
In Security and Risk Management, the guide points to bringing ML models and large language models into risk management frameworks, governance for AI ethics and algorithmic bias, and checking the security of AI supply chains. In Asset Security, it covers the classification and handling of training datasets, pre-trained models and model weights, data integrity against poisoning, and privacy controls such as differential privacy and data masking.
In Security Architecture and Engineering, it covers input validation against prompt injection and adversarial attacks, shared responsibility for cloud AI services, and explainable AI as a security requirement. In Communication and Network Security, it covers micro-segmentation and Zero Trust Architecture to isolate AI training environments, and AI-driven network detection and response.
In Identity and Access Management, it covers identities for AI agents and service accounts under least privilege, plus AI-based behavioral biometrics and adaptive authentication. In Security Assessment and Testing, it covers red teaming of AI systems and testing model robustness against evasion and extraction attacks. In Security Operations, it covers AI in SOAR platforms, alert fatigue and monitoring for model drift. In Software Development Security, it covers risks from AI-assisted coding tools, AI security testing in CI/CD pipelines and the supply chain of ML libraries.
When it applies
The guidance describes the current exam. It does not announce a new CISSP outline or new domain weights. The outline in force is still the one effective April 15, 2024.
Domain weights stay at 16% for Security and Risk Management, 10% for Asset Security, 13% for Security Architecture and Engineering, 13% for Communication and Network Security, 13% for Identity and Access Management, 12% for Security Assessment and Testing, 13% for Security Operations and 10% for Software Development Security.
ISC2 says its exams follow a three-year refresh cycle that starts with a job task analysis. The guidance does not give a date for the next CISSP outline.
What it means for your study
Treat AI as part of every domain, not as a separate chapter. When you study a domain, ask how its controls apply to models, training data, prompts and AI agents.
Use the guide as a checklist next to the official outline. Topics that come up in several domains, such as data poisoning, prompt injection, AI supply chain risk, non-human identities and model drift, deserve a clear answer on risk, control and governance.