Building trustworthy, AI-enabled cybersecurity technologies requires more than technical excellence. It also requires that ethical principles and regulatory requirements be embedded into research and development from the outset, rather than addressed only once the technical work is complete. ATHENA has followed this principle since the start of the project, adopting an ethics- and compliance-by-design approach. With the recent completion of the Ethics & Regulatory Compliance Handbook (Deliverable D12.2), we would like to present the methodological framework underpinning this work: the Ethics and Regulatory Governance (ERGO) framework, and ETHAI, the project’s dedicated methodology for the governance of AI systems and models.
The ERGO framework
ERGO is structured as an ongoing cycle rather than a single review carried out at one point in the project. Each cycle begins with an assessment of project activities against the applicable ethical principles and EU regulatory framework, combining information gathered from partners with ongoing monitoring and consultation across the consortium.
Where this assessment identifies a potential concern, such as a technical design choice or a data processing operation that may not align with applicable ethical principles or regulatory requirements, it is communicated to the relevant partners and, where necessary, brought to the attention of the consortium as a whole to support corrective actions and risk mitigation measures. All concerns identified during the assessment phase are documented and monitored throughout successive ERGO cycles.
For each concern identified, the corresponding ethical principles and regulatory obligations are translated into project-specific guidance. Dedicated tools, including questionnaires and self-assessment checklists, then support partners in implementing this guidance, with the results feeding into the next assessment cycle.
As this cycle repeats throughout the project, ERGO can respond both to how ATHENA’s technologies develop and to changes in the regulatory environment. Several of the instruments relevant to the project, including the GDPR, the AI Act, the Cybersecurity Act and the NIS2 Directive, are currently subject to revision proposals at EU level, and monitoring these developments is part of ERGO’s ongoing work.

ETHAI: AI governance within ERGO
AI-based functionalities are central to ATHENA’s technical solutions. To address the ethical and regulatory requirements specifically applicable to these systems and models, the project established ETHAI as a dedicated methodology within ERGO, focused on the assessment and governance of the AI systems and models developed in ATHENA.
ETHAI is grounded in the seven requirements set out in the EU Ethics Guidelines for Trustworthy AI, namely: human agency and oversight; technical robustness and safety; privacy and data governance; transparency; diversity, non-discrimination, and fairness; societal and environmental well-being; and accountability. It also incorporates the requirements introduced by the AI Act.
Within ERGO, ETHAI follows the same iterative logic, applied specifically to AI systems and models, through a three-step cycle. Applicable requirements are first identified for each system or model, in light of the relevant EU ethics and legal framework, its intended purpose, and its potential risks and impacts. These requirements are then communicated to the relevant partners together with practical implementation guidance. Their implementation is subsequently assessed using dedicated tools, including questionnaires, structured checklists, and an adapted version of the Assessment List for Trustworthy AI (ALTAI), allowing any shortcomings or risks to be identified, reported and addressed. The results feed back into the first step of the following cycle, allowing requirements and guidance to be refined as ATHENA’s AI systems and models are developed further.
The baseline assessment
The first application of ERGO and ETHAI was a baseline assessment carried out during the first nine months of the project, drawing on input from consortium partners and a review of relevant project material. On this basis, five areas were identified as requiring attention as the project progresses: the involvement of human participants in research activities; privacy and personal data protection; the governance and ethics of AI; compliance with the EU cybersecurity regulatory framework; and the potential misuse of project results. These are not indications that anything is currently non-compliant, but rather the areas to which subsequent ERGO assessment cycles will pay particular attention.
Looking ahead
Ethics and regulatory governance are continuous processes within ATHENA. As research activities and technological developments progress, ERGO and ETHAI will continue to support the assessment of ethics and regulatory aspects, monitor developments in the European legal framework, and contribute to the refinement of project guidance. In this way, ATHENA aims to ensure that innovation in AI-enabled cybersecurity is accompanied by robust ethics and regulatory governance throughout the project.


