A Systematic Literature Review of AI-Driven Security Assessment and Regulatory Compliance in Cloud-Edge Environments
Published: 2026
Abstract
Cloud and edge systems increasingly depend on AI to address evolving security threats. This reliance underscores the importance of regulatory compliance. Although global regulations such as GDPR and HIPAA have been widely examined, national regulatory frameworks remain insufficiently explored. This paper systematically reviews AI-driven approaches for security assessments in cloud-edge environments, focusing on their adherence to regulatory compliance requirements. The review followed the PRISMA 2020 guidelines to identify, screen, and analyze 30 studies published between 2020 to 2025 from databases such as IEEE Xplore and SpringerLink. Approximately 40% of the studies use Federated Learning (FL), while 30% use NLP techniques. The analysis reveals that 80% of the studies examined GDPR, while HIPAA and the EU AI Act received minimal attention. As a result, the review highlights a lack of unified frameworks integrating security with compliance. This limitation reduces applicability for non-EU regulations such as Saudi Arabia’s NCA and PDPL. To address these gaps, this paper presents the E-EDGE-GRC framework. It uses a multi-level architecture and a maturity scoring system to automate compliance with Saudi national requirements and global standards. These findings and the proposed framework offer a basis for unified, multi-regulatory AI security assessments.
Keywords
A Systematic Literature Review of AI-Driven Security Assessment and Regulatory Compliance in Cloud-Edge Environments is licensed under CC BY 4.0
References
- Mahajan, S., Agarwal, R., & Gupta, M. (2025). Algorithmic bias under the EU AI Act: Compliance risk, capital strain, and pricing distortions in life and health insurance underwriting. Risks, 13, Article 160. https://doi.org/10.3390/risks13090160
- Kusche, I. (2024). Possible harms of artificial intelligence and the EU AI act: Fundamental rights and risk. Journal of Risk Research, 1-14. https://doi.org/10.1080/13669877.2024.2350720
- Tauqeer, A., Kurteva, A., Chhetri, T. R., Ahmeti, A., & Fensel, A. (2022). Automated GDPR contract compliance verification using knowledge graphs. Information, 13, Article 447. https://doi.org/10.3390/info13100447
- Truong, N., Sun, K., Wang, S., Guitton, F., & Guo, Y. (2021). Privacy preservation in federated learning: An insightful survey from the GDPR perspective. Computers & Security, 110, Article 102402. https://doi.org/10.1016/j.cose.2021.102402
- Kalodanis, K., Feretzakis, G., Anastasiou, A., Rizomiliotis, P., Anagnostopoulos, D., & Koumpouros, Y. (2025). A privacy-preserving and attack-aware AI approach for high-risk healthcare systems under the EU AI Act. Electronics, 14, Article 1385. https://doi.org/10.3390/electronics14071385
- Jørgensen, B. N., & Ma, Z. G. (2025). Impact of EU regulations on AI adoption in smart city solutions: A review of regulatory barriers, technological challenges, and societal benefits. Information, 16, Article 568. https://doi.org/10.3390/info16070568
- Feretzakis, G., Vagena, E., Kalodanis, K., Peristera, P., Kalles, D., & Anastasiou, A. (2025). GDPR and large language models: Technical and legal obstacles. Future Internet, 17, Article 151. https://doi.org/10.3390/fi17040151
- Kaissis, G. A., Makowski, M. R., Rückert, D., & Braren, R. F. (2020). Secure, privacy-preserving and federated machine learning in medical imaging. Nature Machine Intelligence, 2, 305-311. https://doi.org/10.1038/s42256-020-0186-1
- Zhao, Y., Zhao, J., Yang, M., Wang, T., Wang, N., Lyu, L., Niyato, D., & Lam, K. Y. (2020). Local differential privacy-based federated learning for internet of things. IEEE Internet of Things Journal, 8, 8836-8853. https://doi.org/10.1109/jiot.2020.3037194
- Blanco-Justicia, A., Domingo-Ferrer, J., Martínez, S., Sánchez, D., Flanagan, A., & Tan, K. E. (2021). Achieving security and privacy in federated learning systems: Survey, research challenges and future directions. Engineering Applications of Artificial Intelligence, 106, Article 104468. https://doi.org/10.1016/j.engappai.2021.104468
- Abbas, Z., Ahmad, S. F., Anjum, A., Syed, M. H., Malik, S. U. R., & Rehman, S. (2025). Ensuring zero-trust in GDPR-compliant deep federated learning architecture. Computers, 14, Article 317. https://doi.org/10.3390/computers14080317
- Chhetri, T. R., Kurteva, A., DeLong, R. J., Hilscher, R., Korte, K., & Fensel, A. (2022). Data protection by design tool for automated GDPR compliance verification based on semantically modeled informed consent. Sensors, 22, Article 2763. https://doi.org/10.3390/s22072763
- Hamdani, R. E., Mustapha, M., Amariles, D. R., Troussel, A., Meeùs, S., & Krasnashchok, K. (2021). A combined rule-based and machine learning approach for automated GDPR compliance checking. ACM, 40-49. https://doi.org/10.1145/3462757.3466081
- Sánchez, D., Viejo, A., & Batet, M. (2021). Automatic assessment of privacy policies under the GDPR. Applied Sciences, 11, Article 1762. https://doi.org/10.3390/app11041762
- Cejas, O. A., Azeem, M. I., Abualhaija, S., & Briand, L. C. (2023). NLP-based automated compliance checking of data processing agreements against GDPR. IEEE Transactions on Software Engineering, 49, 4282-4303. https://doi.org/10.1109/tse.2023.3288901
- Tokas, S., Owe, O., & Ramezanifarkhani, T. (2021). Static checking of GDPR-related privacy compliance for object-oriented distributed systems. Journal of Logical and Algebraic Methods in Programming, 125, Article 100733. https://doi.org/10.1016/j.jlamp.2021.100733
- Brauneck, A., Schmalhorst, L., Majdabadi, M. M. K., Bakhtiari, M., Völker, U., Baumbach, J., Baumbach, L., & Buchholtz, G. (2023). Federated machine learning, privacy-enhancing technologies, and data protection laws in medical research: Scoping review. Journal of Medical Internet Research, 25, Article e41588. https://doi.org/10.2196/41588
- Granata, D., Mastroianni, M., Rak, M., Cantiello, P., & Salzillo, G. (2024). GDPR compliance through standard security controls: An automated approach. Journal of High Speed Networks, 30, 147-174. https://doi.org/10.3233/jhs-230080
- Lyu, L., Yu, H., Ma, X., Chen, C., Sun, L., Zhao, J., Yang, Q., & Yu, P. S. (2022). Privacy and robustness in federated learning: Attacks and defenses. IEEE Transactions on Neural Networks and Learning Systems, 35, 8726-8746. https://doi.org/10.1109/tnnls.2022.3216981
- Pattakou, A., Diamantopoulou, V., Kalloniatis, C., & Gritzalis, S. (2024). A unified framework for GDPR compliance in cloud computing. ACM, 1-9. https://doi.org/10.1145/3664476.3670918
- Karunaratne, T. (2021). For learning analytics to be sustainable under GDPR—Consequences and way forward. Sustainability, 13, Article 11524. https://doi.org/10.3390/su132011524
- Lee, G. H., & Shin, S. Y. (2020). Federated learning on clinical benchmark data: Performance assessment. Journal of Medical Internet Research, 22, Article e20891. https://doi.org/10.2196/20891
- Luo, L., Meng, S., Qiu, X., & Dai, Y. (2019). Improving failure tolerance in large-scale cloud computing systems. IEEE Transactions on Reliability, 68, 620-632. https://doi.org/10.1109/TR.2019.2901194
- Strickx, T., & Hartman, J. (2022). Cloudflare outage on June 21, 2022. In The Cloudflare Blog. https://blog.cloudflare.com/cloudflare-outage-on-june-21-2022/
- Campos, E. M., Saura, P. F., González-Vidal, A., Hernández-Ramos, J. L., Bernabé, J. B., Baldini, G., & Skarmeta, A. (2021). Evaluating federated learning for intrusion detection in internet of things: Review and challenges. Computer Networks, 203, Article 108661. https://doi.org/10.1016/j.comnet.2021.108661
- Korányi, R., Mancera, J. A., & Kaufmann, M. (2022). GDPR-compliant social network link prediction in a graph DBMS: The case of know-how development at Beekeeper. Knowledge, 2, 286-309. https://doi.org/10.3390/knowledge2020017
- Feretzakis, G., Papaspyridis, K., Gkoulalas-Divanis, A., & Verykios, V. S. (2024). Privacy-preserving techniques in generative AI and large language models: A narrative review. Information, 15, Article 697. https://doi.org/10.3390/info15110697
- Rawindaran, N., Nawaf, L., Alarifi, S., Alghazzawi, D., Carroll, F., Katib, I., & Hewage, C. (2023). Enhancing cyber security governance and policy for SMEs in industry 5.0: A comparative study between Saudi Arabia and the United Kingdom. Digital, 3, 200-231. https://doi.org/10.3390/digital3030014
- Lepri, B., Oliver, N., & Pentland, A. (2021). Ethical machines: The human-centric use of artificial intelligence. iScience, 24, Article 102249. https://doi.org/10.1016/j.isci.2021.102249
- Choudhury, A., Volmer, L., Martin, F., Fijten, R., Wee, L., Dekker, A., & Van Soest, J. (2024). Advancing privacy-preserving health care analytics and implementation of the Personal Health Train: Federated deep learning study. JMIR AI, 4, Article e60847. https://doi.org/10.2196/60847
- Khan, L. U., Pandey, S. R., Tran, N. H., Saad, W., Han, Z., Nguyen, M. N. H., & Hong, C. S. (2020). Federated learning for edge networks: Resource optimization and incentive mechanism. IEEE Communications Magazine, 58, 88-93. https://doi.org/10.1109/MCOM.001.1900649
- J. Trivedi, M. Tahir and J. Isoaho, "AI-Enhanced Threat Intelligence in Remote Patient Monitoring Systems: A Survey on Recent Advances, Challenges and Future Research Directions," in IEEE Access, vol. 13, pp. 106465-106488, 2025, doi: 10.1109/ACCESS.2025.3572626.
