惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

WordPress大学
WordPress大学
小众软件
小众软件
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - Franky
Jina AI
Jina AI
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Y
Y Combinator Blog
V
Visual Studio Blog
C
Check Point Blog
阮一峰的网络日志
阮一峰的网络日志
U
Unit 42
量子位
人人都是产品经理
人人都是产品经理
博客园 - 聂微东
M
MIT News - Artificial intelligence
爱范儿
爱范儿
B
Blog RSS Feed
MyScale Blog
MyScale Blog
H
Help Net Security
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
美团技术团队
L
LangChain Blog
D
Docker

Cloud Security Alliance

SearchLeak: Copilot Data Exfiltration Exploited | CSA Zero-Trust AI Governance for Multi-Agent Systems | CSA Dangling CNAMEs: Hidden Cloud Risk | CSA Agentic Payments in Financial Services | CSA Mythos and the Future of Cybersecurity | CSA AI-Driven Cloud Risk: Defenders Lose Ground | CSA Financial Services Industry Shifts from AI Adoption to | CSA CSAI Foundation Announces RiskRubric V2 as the Next Key | CSA RiskRubric Updates: AI Risk Assessment | CSA Over 80% of Organizations that Miss 24-Hour Patch Window Report | CSA ORCHIDEAS & MAESTRO: Secure AI Design | CSA Top 6 Claude Security Risks to Watch | CSA Cloud Cost Optimization in 2026 | CSA HIPAA Rule Overhaul in 2026 | CSA AI-Driven Exploits Outsmart Detection | CSA MCP Risks CISOs Should Prepare For | CSA AI Governance for Trust and Compliance | CSA MTTP: Patch Cycles Too Slow | CSA Cloud Security Evolution: Security Teams Lead | CSA Misconfigurations Break Customer Trust in Apps | CSA Taming Shadow AI: C-Suite Strategies | CSA Agentic AI Threats: Five Powers | CSA AIUC-1: Agentic AI Governance | CSA 2026 Threat Report for CISOs | CSA Securing AI in AWS: Runtime Detection & Response | CSA SLMs, LLMs, and the DSPM Difference | CSA OT Security Timeline: Mythos and Patch Pace | CSA Blast Radius and Cloud Threat Detection | CSA State of AI Cybersecurity 2026: 92% Concerned | CSA AI in MDR for Franchise & Multi-Location Ops | CSA
CSAI Foundation Announces Key Milestones to Secure the Ag...
2026-04-29 · via Cloud Security Alliance

New catastrophic risk initiative, CNA authorization, and strategic agentic AI acquisitions accelerate enterprise AI governance and assurance

SEATTLE – April 29, 2026 — The Cloud Security Alliance (CSA), the world's leading not-for-profit organization committed to AI, cloud, and Zero Trust cybersecurity education, today announced a series of milestones that significantly expand the CSAI Foundation's capacity to deliver on its 2026 mission of Securing the Agentic Control Plane. 

Unveiled at the CSA Agentic AI Security Summit, the announcements include the launch of the STAR for AI Catastrophic Risk Annex (Annex), authorization as a CVE Numbering Authority (CNA) through MITRE, and the acquisition of two foundational agentic-AI specifications.

"The global economy is contending with two exponentials at once: frontier models leapfrogging each other month over month, and viral, bottom-up adoption of agents inside the business," said Jim Reavis, CEO and co-founder, Cloud Security Alliance. "Today's announcements give enterprises, auditors, and regulators the technical specifications and assurance scaffolding to say yes to agentic AI without losing control of it."

Launched with support from Coefficient Giving, a philanthropic organization backing long-horizon AI safety work, the Catastrophic Risk Annex extends CSA’s AI Controls Matrix (AICM) and the broader STAR for AI assurance program to address scenarios involving loss of human oversight, uncontrolled system behavior, and other large-scale, irreversible, society-wide consequences, focusing on what can actually be tested in production. A four-phase rollout will begin in June 2026 and continue through December 2027, aligned with the NIST AI RMF, the EU AI Act, and ISO/IEC 42001, culminating in the inaugural State of Catastrophic AI Risk Controls Report.

CSAI Foundation has also made significant progress in advancing its AI Risk Observatory, a mission made more urgent by rapid model advancement and the growing ability of AI systems to discover, generate, and amplify cybersecurity findings at scale. As part of this work, the Cloud Security Alliance has been authorized by the CVE Program as a CVE Numbering Authority (CNA). Our initial operational scope is addressing vulnerabilities in our software tools. CSAI is now organizing research work streams and operational projects with existing CNAs and ecosystem partners focused on building toward responsible agentic-specific vulnerability coordination, CVE/NVD ecosystem gaps, AI-assisted human-verified vulnerability enrichment and practical guidance for defenders.

The Foundation also strengthened the technical and governance foundations required to secure the agentic control plane through two strategic acquisitions. Thanks to the generosity of CSA corporate member Vanta, the Autonomous Action Runtime Management (AARM) specification — an open system specification for securing AI-driven actions at runtime across context, policy, intent, and behavior — has been contributed to the CSAI Foundation. AARM founder Herman Errico will continue to lead the development of the specification as the working group chair. We are also pleased to announce an agreement with Josh Woodruff, founder of MassiveScale.AI to transfer stewardship of the Agentic Trust Framework (ATF). Woodruff, a CSA Research Fellow and co-chair of the CSA Zero Trust Working Group, has applied Zero Trust principles to agentic AI to provide a robust governance framework and will continue to lead the development of ATF. 

Learn more about the STAR for AI Catastrophic Risk Annex and the CSAI Foundation and how you can help shape the future of Agentic AI security.

About CSAI Foundation
CSAI is a 501(c)3 non-profit foundation launched by the Cloud Security Alliance, dedicated exclusively to AI security and safety. With a 2026 mission of Securing the Agentic Control Plane, CSAI delivers integrated programs spanning risk intelligence, operational best practices, professional and agent certification, executive collaboration, global assurance, and forward-looking research to govern the autonomous AI economy. Visit www.CSAI.foundation.

About Cloud Security Alliance
The Cloud Security Alliance (CSA) is the world’s leading not-for-profit organization committed to awareness, practical implementation, and credentialing of forward-looking cybersecurity topics, including AI, cloud, and Zero Trust. In an era where digital transformation drives business success, CSA stands as the global authority ensuring organizations can operate securely while harnessing cutting-edge technology. Through the 501(c)3 CSAI Foundation, volunteer-driven research, globally-accepted standards, and award-winning vendor-neutral education programs that unite varied associations, governments, chapters, and corporate members, CSA bridges the gap between innovation and pragmatic security execution. Visit CSA’s website to learn more.

Media Contact
Kristina Rundquist
ZAG Communications for the CSA
[email protected]