CSA Expands AI Controls Matrix to 247 Safeguards
The Cloud Security Alliance introduced its vendor-neutral AI Controls Matrix in 2025 to help companies turn broad principles for trustworthy artificial intelligence into operational safeguards. The framework extends cloud-security practices to generative AI and AI agents, assigning responsibilities across model providers, application developers, orchestration platforms, cloud operators and customers. It addresses risks including prompt injection, model poisoning, unauthorized access, exposed model weights and sensitive-data leakage throughout an AI system’s lifecycle.
CSA released AICM version 1.1 on June 22, 2026, and detailed the update on July 14. The framework now contains 247 control objectives across 18 security domains, up from 243 controls in the original edition, while the accompanying AI Consensus Assessment Initiative Questionnaire has expanded to 320 questions. The controls cover stages from preparation through retirement and map to major governance regimes and standards, including the EU AI Act, NIST AI RMF, ISO/IEC 42001 and BSI AIC4.
All Coverage
2 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →