Journal of Cyber Security and Risk Auditing

Journal of Cyber Security and Risk Auditing

ISSN: 3079-5354 (Online)

Publishing model:

: Open access
Scopus Indexed
2025
14.7

CiteScore

Q1
open accessOpen Access

Article

👁️0views

A Systematic Literature Review of AI-Driven Security Assessment and Regulatory Compliance in Cloud-Edge Environments

by 

Rasha Almarshood Orcid link ;

Abdullah Albuali Orcid link

PDF logoPDF

Published: 2026

Abstract

Cloud and edge systems increasingly depend on AI to address evolving security threats. This reliance underscores the importance of regulatory compliance. Although global regulations such as GDPR and HIPAA have been widely examined, national regulatory frameworks remain insufficiently explored. This paper systematically reviews AI-driven approaches for security assessments in cloud-edge environments, focusing on their adherence to regulatory compliance requirements. The review followed the PRISMA 2020 guidelines to identify, screen, and analyze 30 studies published between 2020 to 2025 from databases such as IEEE Xplore and SpringerLink. Approximately 40% of the studies use Federated Learning (FL), while 30% use NLP techniques. The analysis reveals that 80% of the studies examined GDPR, while HIPAA and the EU AI Act received minimal attention. As a result, the review highlights a lack of unified frameworks integrating security with compliance. This limitation reduces applicability for non-EU regulations such as Saudi Arabia’s NCA and PDPL. To address these gaps, this paper presents the E-EDGE-GRC framework. It uses a multi-level architecture and a maturity scoring system to automate compliance with Saudi national requirements and global standards. These findings and the proposed framework offer a basis for unified, multi-regulatory AI security assessments.

Keywords

Artificial IntelligenceSecurity AssessmentCloud ComputingEdge ComputingRegulatory ComplianceGDPREU AI ActFederated Learning.

References

  1. Mahajan, S., Agarwal, R., & Gupta, M. (2025). Algorithmic bias under the EU AI Act: Compliance risk, capital strain, and pricing distortions in life and health insurance underwriting. Risks, 13, Article 160. https://doi.org/10.3390/risks13090160
  2. Kusche, I. (2024). Possible harms of artificial intelligence and the EU AI act: Fundamental rights and risk. Journal of Risk Research, 1-14. https://doi.org/10.1080/13669877.2024.2350720
  3. Tauqeer, A., Kurteva, A., Chhetri, T. R., Ahmeti, A., & Fensel, A. (2022). Automated GDPR contract compliance verification using knowledge graphs. Information, 13, Article 447. https://doi.org/10.3390/info13100447
  4. Truong, N., Sun, K., Wang, S., Guitton, F., & Guo, Y. (2021). Privacy preservation in federated learning: An insightful survey from the GDPR perspective. Computers & Security, 110, Article 102402. https://doi.org/10.1016/j.cose.2021.102402
  5. Kalodanis, K., Feretzakis, G., Anastasiou, A., Rizomiliotis, P., Anagnostopoulos, D., & Koumpouros, Y. (2025). A privacy-preserving and attack-aware AI approach for high-risk healthcare systems under the EU AI Act. Electronics, 14, Article 1385. https://doi.org/10.3390/electronics14071385
  6. Jørgensen, B. N., & Ma, Z. G. (2025). Impact of EU regulations on AI adoption in smart city solutions: A review of regulatory barriers, technological challenges, and societal benefits. Information, 16, Article 568. https://doi.org/10.3390/info16070568
  7. Feretzakis, G., Vagena, E., Kalodanis, K., Peristera, P., Kalles, D., & Anastasiou, A. (2025). GDPR and large language models: Technical and legal obstacles. Future Internet, 17, Article 151. https://doi.org/10.3390/fi17040151
  8. Kaissis, G. A., Makowski, M. R., Rückert, D., & Braren, R. F. (2020). Secure, privacy-preserving and federated machine learning in medical imaging. Nature Machine Intelligence, 2, 305-311. https://doi.org/10.1038/s42256-020-0186-1
  9. Zhao, Y., Zhao, J., Yang, M., Wang, T., Wang, N., Lyu, L., Niyato, D., & Lam, K. Y. (2020). Local differential privacy-based federated learning for internet of things. IEEE Internet of Things Journal, 8, 8836-8853. https://doi.org/10.1109/jiot.2020.3037194
  10. Blanco-Justicia, A., Domingo-Ferrer, J., Martínez, S., Sánchez, D., Flanagan, A., & Tan, K. E. (2021). Achieving security and privacy in federated learning systems: Survey, research challenges and future directions. Engineering Applications of Artificial Intelligence, 106, Article 104468. https://doi.org/10.1016/j.engappai.2021.104468
  11. Abbas, Z., Ahmad, S. F., Anjum, A., Syed, M. H., Malik, S. U. R., & Rehman, S. (2025). Ensuring zero-trust in GDPR-compliant deep federated learning architecture. Computers, 14, Article 317. https://doi.org/10.3390/computers14080317
  12. Chhetri, T. R., Kurteva, A., DeLong, R. J., Hilscher, R., Korte, K., & Fensel, A. (2022). Data protection by design tool for automated GDPR compliance verification based on semantically modeled informed consent. Sensors, 22, Article 2763. https://doi.org/10.3390/s22072763
  13. Hamdani, R. E., Mustapha, M., Amariles, D. R., Troussel, A., Meeùs, S., & Krasnashchok, K. (2021). A combined rule-based and machine learning approach for automated GDPR compliance checking. ACM, 40-49. https://doi.org/10.1145/3462757.3466081
  14. Sánchez, D., Viejo, A., & Batet, M. (2021). Automatic assessment of privacy policies under the GDPR. Applied Sciences, 11, Article 1762. https://doi.org/10.3390/app11041762
  15. Cejas, O. A., Azeem, M. I., Abualhaija, S., & Briand, L. C. (2023). NLP-based automated compliance checking of data processing agreements against GDPR. IEEE Transactions on Software Engineering, 49, 4282-4303. https://doi.org/10.1109/tse.2023.3288901
  16. Tokas, S., Owe, O., & Ramezanifarkhani, T. (2021). Static checking of GDPR-related privacy compliance for object-oriented distributed systems. Journal of Logical and Algebraic Methods in Programming, 125, Article 100733. https://doi.org/10.1016/j.jlamp.2021.100733
  17. Brauneck, A., Schmalhorst, L., Majdabadi, M. M. K., Bakhtiari, M., Völker, U., Baumbach, J., Baumbach, L., & Buchholtz, G. (2023). Federated machine learning, privacy-enhancing technologies, and data protection laws in medical research: Scoping review. Journal of Medical Internet Research, 25, Article e41588. https://doi.org/10.2196/41588
  18. Granata, D., Mastroianni, M., Rak, M., Cantiello, P., & Salzillo, G. (2024). GDPR compliance through standard security controls: An automated approach. Journal of High Speed Networks, 30, 147-174. https://doi.org/10.3233/jhs-230080
  19. Lyu, L., Yu, H., Ma, X., Chen, C., Sun, L., Zhao, J., Yang, Q., & Yu, P. S. (2022). Privacy and robustness in federated learning: Attacks and defenses. IEEE Transactions on Neural Networks and Learning Systems, 35, 8726-8746. https://doi.org/10.1109/tnnls.2022.3216981
  20. Pattakou, A., Diamantopoulou, V., Kalloniatis, C., & Gritzalis, S. (2024). A unified framework for GDPR compliance in cloud computing. ACM, 1-9. https://doi.org/10.1145/3664476.3670918
  21. Karunaratne, T. (2021). For learning analytics to be sustainable under GDPR—Consequences and way forward. Sustainability, 13, Article 11524. https://doi.org/10.3390/su132011524
  22. Lee, G. H., & Shin, S. Y. (2020). Federated learning on clinical benchmark data: Performance assessment. Journal of Medical Internet Research, 22, Article e20891. https://doi.org/10.2196/20891
  23. Luo, L., Meng, S., Qiu, X., & Dai, Y. (2019). Improving failure tolerance in large-scale cloud computing systems. IEEE Transactions on Reliability, 68, 620-632. https://doi.org/10.1109/TR.2019.2901194
  24. Strickx, T., & Hartman, J. (2022). Cloudflare outage on June 21, 2022. In The Cloudflare Blog. https://blog.cloudflare.com/cloudflare-outage-on-june-21-2022/
  25. Campos, E. M., Saura, P. F., González-Vidal, A., Hernández-Ramos, J. L., Bernabé, J. B., Baldini, G., & Skarmeta, A. (2021). Evaluating federated learning for intrusion detection in internet of things: Review and challenges. Computer Networks, 203, Article 108661. https://doi.org/10.1016/j.comnet.2021.108661
  26. Korányi, R., Mancera, J. A., & Kaufmann, M. (2022). GDPR-compliant social network link prediction in a graph DBMS: The case of know-how development at Beekeeper. Knowledge, 2, 286-309. https://doi.org/10.3390/knowledge2020017
  27. Feretzakis, G., Papaspyridis, K., Gkoulalas-Divanis, A., & Verykios, V. S. (2024). Privacy-preserving techniques in generative AI and large language models: A narrative review. Information, 15, Article 697. https://doi.org/10.3390/info15110697
  28. Rawindaran, N., Nawaf, L., Alarifi, S., Alghazzawi, D., Carroll, F., Katib, I., & Hewage, C. (2023). Enhancing cyber security governance and policy for SMEs in industry 5.0: A comparative study between Saudi Arabia and the United Kingdom. Digital, 3, 200-231. https://doi.org/10.3390/digital3030014
  29. Lepri, B., Oliver, N., & Pentland, A. (2021). Ethical machines: The human-centric use of artificial intelligence. iScience, 24, Article 102249. https://doi.org/10.1016/j.isci.2021.102249
  30. Choudhury, A., Volmer, L., Martin, F., Fijten, R., Wee, L., Dekker, A., & Van Soest, J. (2024). Advancing privacy-preserving health care analytics and implementation of the Personal Health Train: Federated deep learning study. JMIR AI, 4, Article e60847. https://doi.org/10.2196/60847
  31. Khan, L. U., Pandey, S. R., Tran, N. H., Saad, W., Han, Z., Nguyen, M. N. H., & Hong, C. S. (2020). Federated learning for edge networks: Resource optimization and incentive mechanism. IEEE Communications Magazine, 58, 88-93. https://doi.org/10.1109/MCOM.001.1900649
  32. J. Trivedi, M. Tahir and J. Isoaho, "AI-Enhanced Threat Intelligence in Remote Patient Monitoring Systems: A Survey on Recent Advances, Challenges and Future Research Directions," in IEEE Access, vol. 13, pp. 106465-106488, 2025, doi: 10.1109/ACCESS.2025.3572626.
SCImago Journal & Country Rank