Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.




Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.

CSAI FoundationChaptersEventsBlog
Join this August 11 webinar to explore practical strategies for managing cloud complexity and AI-driven workloads →
Part of Future Forward Initiatives Project kickoff · June 2026
A CSAI Foundation project

Catastrophic Risk Annex

Turning existential AI concern into auditable controls — an expert-led extension of the AI Controls Matrix, validated through real pilot audits.

June 2026
Kickoff
Dec 2027
Target completion
Grant-funded
Independent & public-interest
AICM
Controls Matrix extension
Founding Benefactor
Coefficient Giving

Underwriting independent, non-commercial research on the gravest risks of transformational AI — in the public interest.

The mission

Making the gravest risks concrete and auditable

As AI systems approach transformational capability, the risks stop being purely theoretical. The Catastrophic Risk Annex convenes AI safety, cybersecurity, and national-security professionals to define a concrete set of catastrophic-AI controls — extending the AI Controls Matrix — and to prove those controls work through pilot audits with real organizations.

The approach

Define, convene, validate

1.

Define catastrophic-AI controls

Author a rigorous control set extending the AICM, targeting the failure modes that could cause catastrophic or existential harm.

2.

Convene an Expert Group

An interdisciplinary group of AI safety, cybersecurity, and national-security professionals authors and stress-tests the controls.

3.

Validate via pilot audits

Prove the controls are auditable and meaningful by running pilot audits against real AI systems and organizations.

Timeline

From kickoff to validated controls

June 2026

Kickoff

Expert Group convened; scope and control taxonomy defined.

2026–2027

Authoring

Draft the catastrophic-AI control set as an AICM extension.

2027

Pilot audits

Validate controls against real systems; refine on findings.

Dec 2027

Completion

Published, validated Catastrophic Risk Annex.

Who's involved

An interdisciplinary Expert Group

Three disciplines, one table

Catastrophic risk sits at the intersection of fields that rarely share a framework. The Annex deliberately brings them together.

AI Safety Cybersecurity National Security

The Expert Group

An interdisciplinary Expert Group is convened and at work authoring and stress-testing the controls, with the AI Resilience Center of Excellence as a stakeholder. Membership is open to qualified experts and CSAI Foundation Executive Advisory Committee members.

Leadership

Project co-leads

Daniele Catteddu
Daniele Catteddu
Chief Technology Officer, Cloud Security Alliance
John Yeoh
John Yeoh
Chief Scientific Officer, Cloud Security Alliance

Join or monitor the Annex

Executive Advisory Committee members and qualified experts can join the Expert Group; organizations can express interest in a pilot audit.