Latest Work Products
Click to read online or download. All resources are freely available — tracking helps CoSAI understand which guidance is most valuable to practitioners.
January 20, 2026
Securing the AI Agent Revolution: A Practical Guide to Model Context Protocol Security
Practical security guidance for organizations deploying MCP-based agentic systems — threat models, access controls, and secure implementation patterns.
October 30, 2025
Defending AI Systems: A New Framework for Incident Response in the Age of Intelligent Technology
A structured framework for security teams responding to AI-specific incidents, including detection, containment, and recovery playbooks.
September 29, 2025
Building Trust in AI Supply Chains: Why Model Signing Is Critical for Enterprise Security
Why cryptographic signing of ML artifacts is a foundational enterprise security control, and how organizations can implement it today.
July 16, 2025
Announcing the CoSAI Principles for Secure-by-Design Agentic Systems
Core principles for designing autonomous AI agents with security as a foundational property — trust boundaries, privilege minimization, and auditability.
July 15, 2025
The AI Security Wake-Up Call: Why Your Organization Needs to Act Now
A call to action for security leaders on the urgency of proactive AI security investment, with concrete first steps for organizations at any maturity level.
June 25, 2025
The AI Supply Chain Security Imperative: 6 Critical Controls Every Executive Must Implement
Six prioritized security controls for executives overseeing AI programs, with implementation guidance and risk framing for board-level conversations.
Complete whitepapers, working drafts, and all workstream repos at github.com/cosai-oasis
Stay Connected
Get Updates from CoSAI
Share your contact details to receive notifications when new security guidance is published and to stay engaged with the CoSAI community.
- New guidance and white papers as they're released
- Invitations to workstream calls and CoSAI events
- Sponsorship and membership information
- Updates from all four active workstreams
CoSAI operates under OASIS Open. Information is handled per the OASIS Privacy Policy.