CoSAI Year 2: The Future of Agentic Security The Coalition for Secure AI (CoSAI) released a landmark report on agentic security, 'The Future of Agentic Security: From Chatbots to Autonomous Swarms,' alongside new research on MCP security threats and agentic identity unveiled at RSAC 2026. CoSAI's Year Two achievements include published guidance on signing ML artifacts, MCP security, and a shared responsibility framework, addressing security challenges in autonomous agent systems. Who’s Responsible When AI Goes Wrong? A New Framework Aims to Answer That Question May 28, 2026Launched at the Aspen Security Forum two years ago, the Coalition for Secure AI CoSAI set out with a clear purpose: to establish a collaborative, open frameworks for safeguarding AI systems. Since then, the AI landscape has evolved at an unprecedented pace, making the demand for shared best practices and cross-industry cooperation more important than ever. Driven by the passion and commitment of our community, sponsors, and Workstream contributors, CoSAI has since published crucial guidance spanning topics from Signing ML Artifacts, MCP Security and a Shared Responsibility Framework. Here’s an overview of CoSAI’s Year Two achievements. Agentic AI systems introduce security challenges that traditional frameworks were never designed to handle — and CoSAI is leading the effort to close that gap. CoSAI’s agentic security work spans the full picture: from The Future of Agentic Security: From Chatbots to Autonomous Swarms — a landmark report illustrating how autonomous agent swarms are already operating in enterprise environments today and what it will take to secure them — to major research papers on MCP security threats and agentic identity unveiled at RSAC 2026. Together, this body of work reflects CoSAI’s commitment to staying ahead of the security challenges that matter most. Read the full Future of Agentic Security Report https://www.coalitionforsecureai.org/wp-content/uploads/2026/03/the-future-of-agentic-security.pdf Explore the research: The MCP Security Question Everyone Kept Asking https://www.coalitionforsecureai.org/after-rsac-2026-the-mcp-security-question-everyone-kept-asking/ New Agentic Identity & Security Research https://www.coalitionforsecureai.org/coalition-for-secure-ai-unveils-new-agentic-identity-and-security-research-following-high-profile-sessions-at-rsac-2026/ Listen to the podcast: The Agentic Identity Problem No One Has Solved Yet https://youtu.be/YzW5onw1860?si=U2c4BpjWzRCmtTah CoSAI’s mission is to share and create best practices for secure AI deployment and to collaborate on AI security research and product development. This work is divided across four workstreams and several Special Interest Groups SIGs . Workstream 2: Preparing Defenders for a Changing Cybersecurity Landscape - Zero Trust SIG - Telemetry SIG Workstream 3: AI Security Risk Governance Workstream - CoSAI Risk- Map SIG: developed a framework for identifying, analyzing, and mitigating security risks in AI systems. - Security of AI-Assisted Code Development SIG: Secure AI-assisted code generation and review. Guidance, tooling patterns, and hardening methods. - Shared Responsibility Framework SRF & Governance, Risk, and Compliance GRC SIG Workstream 4: Secure Design Patterns for Agentic Systems - Security of Agent Development Lifecycle SIG: addresses the critical security challenge of deploying autonomous agents safely in enterprise environments. - Agent Credentials RFC Group - Multimodal Agentic Security RFC Group If you are interested in contributing to any of the SIGs, please see the CoSAI meeting calendar https://lists.oasis-open-projects.org/g/cosai-op/calendar . Keep up with the fast-moving landscape of AI development and the critical and emerging challenges in AI security with CoSAI’s latest research. AI Shared Responsibility Framework and– May 2026 Blog Agentic Identity and Access Management and– April 2026 Blog – March 2026 The Future of Agentic Security: From Chatbots to Autonomous Swarms Model Context Protocol MCP Security and– January 2026 Blog AI Incident Response Framework and– October 2025 Blog and Signing ML Artifacts: Building towards tamper-proof ML metadata records – September 2025 Blog Securing AI is not a challenge any one organization can solve alone and CoSAI has always believed that the strongest defenses are built through community. That’s why we’re proud to highlight the growing circle of trusted industry leaders who are helping shape the future of AI security alongside us. We are excited to welcome OWASP , the AI Alliance , and the Cloud Security Alliance to CoSAI’s Technical Steering Committee. These organizations bring decades of collective expertise, global reach, and deeply respected voices in cybersecurity, open-source development, and responsible AI. Their participation in discussions shaping CoSAI’s technical roadmap ensures that efforts across various organizations are aligned and best practices are shared between different groups. Their participation signals not only a shared commitment to securing AI systems, but a recognition that CoSAI’s work is at the forefront of this critical conversation. Year Two has been a testament to what a committed, collaborative community can achieve. From the milestones we’ve reached to the ecosystem we’ve helped shape, every accomplishment reflected here belongs to the people who showed up, contributed, and believed in CoSAI’s mission. As we look ahead, we carry that momentum forward — together. More Security Guidance coming soon: - WS1: AIMM: Artifact Integrity Maturity Model for AI/ML Supply Chain Trust and Provenance - WS2: Zero Trust for AI Systems Publication - WS4: MCP Security Guidance, version 2 If you or your organization are interested in learning more about CoSAI or if you want to actively support our mission, please visit our Get Involved https://www.coalitionforsecureai.org/get-involved/ page for more information. Thank you for being part of something that truly matters