CSA Research Publications
Whitepapers, Reports and Other Resources
Browse Publications
![]() | AISI: Open-Weight Models Close Cyber Capability Gap Release Date: 08/09/2026 Key Takeaways The UK AI Security Institute (AISI) has found that the leading open-weight AI models now trail frontier closed models on offensive cyber tasks ... Request to download |
![]() | Four AI Escapes: A Systemic Governance Risk Reading Release Date: 08/09/2026 What Sandbox and Containment Failures at OpenAI and Anthropic Reveal About Evaluation Governance. Key Takeaways Between July 21 and July 30, 2026, OpenAI and... Request to download |
![]() | EU AI Act Article 50: Transparency Obligations Take Effect Release Date: 07/28/2026 Learn what the EU AI Act's Article 50 transparency requirements mean for AI providers and deployers. This publication explains the new disclosure obligations... Request to download |
Hugging Face Incident Initial Post-Mortem Release Date: 07/27/2026 Examine CSA’s analysis of the first publicly documented autonomous AI attack. Learn how the incident unfolded, why traditional defenses fell short, and the p... Request to download | |
![]() | Every Frontier Model Cheated: What AISI's Findings Mean for Trust Release Date: 07/26/2026 Key Takeaways The UK AI Security Institute (AISI) reported on July 21, 2026 that every one of the five frontier models it evaluated for cybersecurity capabil... Request to download |
![]() | Hugging Face's Autonomous AI Agent Breach Release Date: 07/19/2026 Security Implications and Guidance for Agentic-Attacker Incidents. Key Takeaways Hugging Face disclosed on July 16, 2026 that an intrusion into its productio... Request to download |
![]() | Agent Data Injection: A New Attack Class Beyond Prompt Injection Release Date: 07/16/2026 How Corrupted Metadata Bypasses Existing Agent Defenses. Agent Data Injection: A New Attack Class Beyond Prompt Injection Key Takeaways Researchers from Seou... Request to download |
![]() | Gold Eagle: The White House's AI Vulnerability Clearinghouse Release Date: 07/15/2026 What the New Federal Coordination Model Means for Critical Infrastructure Operators. Key Takeaways The White House announced Gold Eagle on July 15, 2026, a f... Request to download |
![]() | Project Glasswing: AI Discovery Outpaces Open Source Patching Capacity Release Date: 06/07/2026 1,596 Vulnerabilities Disclosed to Maintainers — Only 97 Fixed. Key Takeaways Project Glasswing, Anthropic's coordinated AI vulnerability research initiative... Request to download |
![]() | Release Date: 06/02/2026 How Agentic AI Support Systems Enable Account Takeover. Helpdesk Hijack Key Takeaways Over the weekend of May 31–June 1, 2026, threat actors exploited Meta's... Request to download |
![]() | NIST AI Consortium: New TEVV Standards for Enterprise Compliance Release Date: 06/02/2026 How the Expanded Consortium's AI TEVV Zero Draft Process Reshapes AI Governance Obligations. NIST AI Consortium: New TEVV Standards for Enterprise Compliance... Request to download |
![]() | The Presidential AI Executive Order and Industry Alignment Release Date: 06/02/2026 An analysis of the June 2, 2026 executive order Promoting Advanced Artificial Intelligence Innovation and Security, reading its vulnerability-clearinghouse, ... Request to download |
