Research

September 16, 2026

Zero Trust for AI Systems: Why Authorization Can’t Live Inside the Model

September 2026 CoSAI’s Preparing Defenders for AI workstream (WS2) has released its latest paper, Zero Trust for AI Systems, a guide for applying one of security’s most established design patterns to the newest category of insider threat: the AI system itself. The timing isn’t abstract. Over the summer, several frontier […]
May 28, 2026

Who’s Responsible When AI Goes Wrong? A New Framework Aims to Answer That Question

When an AI system causes harm or fails a compliance audit, the finger-pointing starts almost immediately. The model provider blames the configuration. The cloud provider points to the tenant. The application team cites model limitations. Our new AI Shared Responsibility Framework is designed to end that cycle before it starts. […]
April 17, 2026

Who’s Minding the Agent? A New Framework for AI Identity and Access Control

An invoice-processing agent with broad financial system access gets manipulated through prompt injection, malicious instructions embedded in the data it reads, and begins initiating fraudulent payments, all under a shared service account with no clear audit trail. A customer-support agent with access to CRM, knowledge-base, and email tools starts combining […]
March 31, 2026

When the Bots Run the Incident Response: What AI Agents Mean for Enterprise Security

Our latest paper maps the security challenges of a world where AI doesn’t just answer questions — it acts. Picture this: it’s 2 a.m., an outage hits your production infrastructure, and no human has noticed yet. Within seconds, an autonomous AI agent wakes up, pulls the relevant logs, creates a […]
October 30, 2025

Defending AI Systems: A New Framework for Incident Response in the Age of Intelligent Technology

The Coalition for Secure AI (CoSAI) has released the AI Incident Response Framework, Version 1.0, which provides security teams with the tools, knowledge, and structured approaches they need to protect AI systems from emerging threats.