The Cloud Security Alliance is treating autonomous AI agents the way it treats any other untrusted actor: with identity, least privilege, and revocable trust.
On April 29, 2026, at the CSA Agentic AI Security Summit, the CSAI Foundation announced a package of milestones under its 2026 mission of “Securing the Agentic Control Plane,” per CSA’s press release. The most relevant piece for security leaders is the Agentic Trust Framework, which CSA took stewardship of from founder Josh Woodruff and describes as applying Zero Trust principles to agentic AI governance.
CSAI also acquired the Autonomous Action Runtime Management spec, an open standard for securing AI-driven actions at runtime across context, policy, intent, and behavior. It was contributed via CSA member Vanta, with founder Herman Errico staying on as working-group chair. Note: the ATF transfer, the AARM acquisition, and a supporting funding relationship with Coefficient Giving are single-sourced to CSA’s release and not independently confirmed.
CSAI separately launched a STAR for AI Catastrophic Risk Annex, extending the AI Controls Matrix to cover loss of oversight and large-scale harms. Its four-phase rollout runs June 2026 through December 2027, mapped to NIST AI RMF, the EU AI Act, and ISO/IEC 42001. Per-phase dates were not disclosed.
Source: Cloud Security Alliance



Leave a Reply