← All posts / Policy

50 Security Chiefs Launch AITSC to Write the Rulebook for Enterprise AI

A new peer-governed consortium of CISOs and security leaders is betting that practitioners — not vendors or regulators — should define how AI is governed inside the world's largest organizations.

50 Security Chiefs Launch AITSC to Write the Rulebook for Enterprise AI

On August 11, 2026, a new kind of standards body opened its doors in San Francisco. The AI Trust and Security Consortium (AITSC) is an independent, peer-governed initiative for enterprise AI — and unlike most industry consortia, it is deliberately small. The founding cohort is capped at just 50 security and technology leaders, drawn from CISOs, CIOs, CTOs, Chief Privacy Officers, and heads of GRC and security architecture who are directly accountable for AI governance at real scale.

The premise is simple and pointed: the people who have to defend enterprise AI systems should be the ones writing the controls. As Balaji Ganesan, CEO of Trust3 AI — the company organizing the initiative — put it, “Security leaders are being asked to underwrite the biggest technology bet of their careers with tools and frameworks that predate the technology. Nobody solves that alone.”

Why now? The governance gap has become a crisis

The numbers behind the launch are stark. McKinsey’s 2026 AI Trust Maturity Survey found that only about one-third of organizations report mature AI governance. Meanwhile, the Linux Foundation reports that 48% of organizations now name security concerns as the top barrier to AI adoption — up from just 17% in 2024. In two years, security has gone from a niche worry to the single biggest brake on enterprise deployment.

The technical reality is even more uncomfortable than the survey data. Agents now hold credentials and take actions autonomously. Models leak data in ways that no traditional DLP (data loss prevention) tool was designed to catch. Third-party AI components show up inside corporate stacks without a procurement ticket. Prompt injection can turn a helpful assistant into an insider threat. As the consortium’s launch materials bluntly note, the frameworks security leaders inherited “were written for software that didn’t reason, didn’t act, and didn’t change its own behavior between Tuesday and Thursday.”

Every enterprise CISO and CIO is living the same contradiction: the board wants AI everywhere by next quarter; engineering already shipped it; legal wants a framework that doesn’t exist; and regulators are drafting rules that will land before anyone is ready.

Who is in the room

The founding members announced so far read like a who’s-who of enterprise data protection:

  • Ulf Mattsson, founder of Protegrity and a veteran of the tokenization and encryption standards wars. “I have spent my career watching data protection standards get written after the damage, not before it,” he said. “Tokenization, encryption, privacy regulation: in every case the practitioners understood the problem years before the frameworks caught up. AI is the same story moving faster.”
  • Maggie Amato, a CISO/BISO leader formerly of Salesforce and Dell. “I am building AI governance in real time, with real deadlines, and the honest truth is that everyone is improvising,” she said. “What I want is not another framework document. I want to know what actually broke at a company my size, what caught it, and what it cost.”
  • Lori Higham, President of Secure Cloud Provider Inc, frames governance as an enabler rather than an obstacle: “Security, compliance, and governance cannot be afterthoughts… they must provide the confidence to move faster.”

What members actually do

AITSC is structured as a working group, not a talk shop. Members co-author reference architectures, control frameworks, and board-ready governance models under collective authorship. Crucially, they also share real incidents and vendor performance data under strict confidentiality — what broke, what caught it, and what it cost. That last category of intelligence is nearly impossible to buy on the open market, and it is the consortium’s most compelling offering.

The consortium is explicitly targeting leaders in regulated and high-stakes environments: financial services, healthcare, pharma, energy, public sector, technology, and retail. Applications are reviewed on a rolling basis, and founding members receive lifetime founding status plus a direct hand in setting the charter and agenda.

The elephant in the room: vendor sponsorship

A fair question hanging over the launch is independence. AITSC may be “peer-governed,” but it is organized and announced by Trust3 AI, a vendor that sells an “agent control plane” — a security product for exactly the problem space the consortium will standardize. The company, founded by Balaji Ganesan, Don Bosco Durai, and Neeraj Sabharwal, is a member of the NVIDIA Inception program and the Snowflake Startup Accelerator.

Industry observers have already flagged this tension. As one skeptical analysis noted, the consortium “entered Google News with a broad promise: define standards that help enterprises deploy artificial intelligence” — but proof is still thin. The history of vendor-backed standards bodies is mixed at best, and the value of AITSC’s output will depend heavily on whether the practitioner cohort genuinely controls the agenda or whether the standards conveniently converge on the sponsor’s product categories.

The counter-argument is equally real: someone has to organize the room, and incumbent standards bodies have been slow. Ulf Mattsson’s own history shows practitioner-led initiatives eventually shaping formal standards — tokenization and encryption controls followed exactly that path.

Context: a standards vacuum

AITSC launches into a broader regulatory flux. In the US, the federal posture has shifted toward voluntary commitments — Reuters reported in early August that Meta, Anthropic, OpenAI, and Google were invited to the White House to discuss voluntary government safety testing. Meanwhile NIST has notably rebranded its flagship AI consortium, dropping “Safety” from the branding — a move widely read as a signal about the agency’s reduced ambitions. Formal, enforceable AI security standards are, in short, not arriving on any predictable timeline.

That vacuum is precisely the opening AITSC is targeting. If fifty vetted practitioners can produce reference architectures and incident data that enterprises actually use, the consortium could become de facto governance infrastructure before regulators catch up. If it degenerates into a vendor marketing channel, it will join the long graveyard of industry consortia that promised much and published little.

Either way, the launch is a signal worth watching: the era of improvising enterprise AI security is ending, and the people who defended those systems in the wild want credit — and control — over what comes next.