Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.




Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.

CSAI FoundationChaptersEventsBlog
Explore the security risks surrounding Model Context Protocol (MCP) servers. Register for this September 16 webinar →

Join the

Autonomous Action Runtime Management (AARM) Working Group

AARM is an open system category specification for securing AI-driven actions at runtime. Build systems that intercept, authorize, and audit autonomous actions before they execute.
Autonomous Action Runtime Management (AARM)

About This Working Group

The Autonomous Action Runtime Management (AARM) Working Group is developing an open, vendor-neutral specification for securing AI-agent actions before they reach connected systems. AARM addresses risks traditional security tools were not designed to manage, including irreversible actions, high-speed execution, excessive privileges, prompt injection, intent drift, and threats that emerge across a sequence of otherwise permitted actions. The specification defines how runtime security systems should intercept actions, evaluate them against policy and user intent, enforce appropriate controls, and create tamper-evident records for accountability.

Members help shape AARM’s threat model, conformance requirements, implementation guidance, architecture patterns, benchmarks, and public review process. The group welcomes security practitioners, researchers, technology providers, buyers, and end users who want to establish a shared foundation for building, evaluating, and advancing runtime security for AI agents.

How Participation Works

Explore how to get involved, from attending meetings to contributing to research and connecting with the community.

Attend Working Sessions

Stay ahead of emerging security trends, influence CSA initiatives, and collaborate directly with industry experts.

Shape Industry Research

Grow your professional reputation by contributing to globally recognized research and helping define industry best practices.

Expand Your Professional Network

Build meaningful connections with security leaders, practitioners, and peers from organizations around the world.

Premier AI Safety Ambassadors

Premier AI Safety Ambassadors play a leading role in promoting AI safety within their organization, advocating for responsible AI practices and promoting pragmatic solutions to manage AI risks. Contact sales@cloudsecurityalliance.org to learn how your organization could participate and take a seat at the forefront of AI safety best practices.

Working Group Leadership

Meet the leaders guiding this Working Group's direction, research priorities, and community collaboration.

Josh Buker
Josh Buker
Research Analyst, CSA

Josh Buker

Research Analyst, CSA

Working Group Co-Chairs

Herman Errico
Herman Errico

Herman Errico

Akul Loomba
Akul Loomba

Akul Loomba

Diana Kelley
Diana Kelley

Diana Kelley

Chris Hughes
Chris Hughes
Founder, Resilient Cyber

Chris Hughes

Founder, Resilient Cyber

 

Chris is the founder of Resilient Cyber, a leading cybersecurity newsletter and podcast reaching tens of thousands weekly. With over 20 years of cybersecurity experience spanning the Department of Defense, Federal Government, and commercial organizations, Chris has held roles including CEO, CISO, Security Engineer, and Security Architect, giving him a practitioner's perspective on the real-world challenges security team...

Read more