SAN FRANCISCO, 15 AUG 2026 — A second industry body for AI security, the AI Trust and Security Consortium, launched on 11 August. It is the second such group to appear in a fortnight, and it is built on the opposite principle from the first.

Where one publishes a taxonomy for everyone, AITSC caps membership at fifty and keeps its incident reports confidential. It assembles fifty people who agree not to repeat what they hear.

What AITSC is

50Membership cap, security and technology leaders
11 AugLaunch date
ConfidentialMembers share real incidents, near-misses and vendor performance under a strict confidentiality agreement
IndividualsFounding members join as named people, not as companies

The founders are Ulf Mattsson, who founded Protegrity; Lori Higham, president of Secure Cloud Provider Inc; and Maggie Amato, a chief information security officer and business information security officer formerly at Salesforce and Dell.

Members co-author reference architectures, control frameworks and what the announcement calls board-ready governance models. The consortium aims to close the gap between what regulators demand of enterprise AI and what existing security frameworks actually cover.

The numbers behind the launch

Two figures are cited, and both are worth keeping.

McKinsey's 2026 AI Trust Maturity Survey found roughly one third of organisations reporting mature AI governance. And Linux Foundation data has security concerns named as the top barrier to AI adoption by 48 per cent of organisations, against 17 per cent in 2024.

The second figure is more telling: security concerns as a blocker to AI adoption have tripled in two years. That suggests an industry which has moved from asking whether AI works to asking whether it can be trusted in production, the point at which governance bodies usually appear.

One phrase in that list is more revealing than it looks. Board-ready governance models names the audience, and the audience is not engineers. It is directors who need to demonstrate that AI risk is being managed, which is a genuine and growing need — and a different product from a technical control. Knowing which of the two you are buying into matters before you spend a security leader's time on it.

The comparison that matters

We covered the other one earlier this month. SAFE — the Shared AI Findings Exchange — was proposed by more than 120 organisations including NVIDIA, Cisco, CrowdStrike, Microsoft and Amazon, as a common taxonomy and a clock for reporting AI agent security incidents.

SAFEAITSC
Members120+ organisations50 individuals, capped
OutputShared taxonomy and reporting clockReference architectures, control frameworks, board material
Incident dataReported into a common schemeShared under strict confidentiality
EnforcementNone statedNone stated

SAFE's value proposition is that everyone can use the taxonomy. AITSC's is that fifty people will tell each other the truth because nobody outside the room will hear it.

Both are coherent propositions. They are also in tension, forcing organisations to choose where a security leader's time is best spent.

What a closed group is good for

The confidentiality is the entire mechanism, not a flaw. There is a strong argument for it.

Security leaders do not discuss their live incidents in public. They cannot: disclosure obligations, litigation exposure, customer relationships and simple embarrassment all push the other way. The result is that the most useful information in the field — what actually went wrong, which vendor underperformed, what the near-miss looked like — circulates privately or not at all.

A small group under agreement is a well-tested way to move that information. Financial-sector information sharing has worked this way for years, and members will tell you it is where the most useful material circulates.

What a closed group cannot produce is a standard. A standard is a document other people can read, implement and be measured against. Fifty people agreeing among themselves on a reference architecture have produced a good internal document and a strong professional network, so the announcement's use of peer-defined standards makes a claim the group's closed structure may not support.

The question neither body answers

Neither SAFE nor AITSC has an enforcement mechanism, an audit obligation or a published membership criterion, and that is the recurring shape of AI security governance right now.

Also notable is who is not present. OpenAI is not a member of SAFE, which we noted when it shipped an offence-grade model to sixteen partners while sitting outside the industry's proposed incident-reporting framework. The frontier laboratories building the systems these bodies are trying to govern are, so far, largely absent from both.

A governance layer composed entirely of the people defending against a technology, with none of the people building it, produces good defensive practice and no leverage.

Why this matters here

For security leaders in this region, whether to engage with either body depends on the organisation.

A fifty-seat cohort will be filled largely from where the founders' networks are, which is North America. That is not a criticism of the founders; it is how professional networks work, and it means the incidents shared will disproportionately reflect North American enterprise environments — different regulators, different cloud footprints, different threat exposure from what a bank in Jakarta or a manufacturer in Penang faces.

SAFE's taxonomy, by contrast, is usable by anyone regardless of membership. For most organisations here, adopting a common vocabulary for agent incidents is the cheaper and more portable move, and it does not require a seat at anything.

ASEAN has no equivalent body, leaving the regional regulators most active on AI — Singapore's IMDA, and Vietnam under its AI law — to produce frameworks without an industry counterpart to argue with them. That is a gap somebody in this region will eventually fill, and the terms will be better set by the people who fill it than inherited from a cohort of fifty in another market.

What we could not establish

The funding model, the membership criteria, whether vendors may join, and whether any output will be published outside the membership. The announcement addresses none of these.

Several points remain unestablished, including whether the fifty seats are filled, how members are selected, whether a fee applies, what the confidentiality agreement covers, and whether AITSC plans any relationship with SAFE or existing standards bodies. We have relied on the launch announcement and its coverage; no independent reporting on the organisation existed at the time of writing.

What to watch

Whether anything is published. A reference architecture that reaches non-members would settle the question of whether this is a standards body or a private forum, and the answer changes who should care.

Whether any frontier laboratory joins either body. That is the difference between a governance layer with leverage and a support group for the people cleaning up.

And whether the seat count holds. Fifty is a deliberate constraint that makes the confidentiality workable, and the pressure to expand it will be considerable if the group turns out to be useful.