AI Controls Matrix v1.1: Strengthening the Foundation for Trustworthy AI

· Source: Cloud Security Alliance · Field: Technology & Digital — Artificial Intelligence & Machine Learning, Cybersecurity & Data Privacy, Robotics & Autonomous Systems · Depth: Intermediate, medium

Summary

The Cloud Security Alliance (CSA) released the AI Controls Matrix (AICM) v1.1 on July 14, 2026, a significant update to its framework for secure and trustworthy AI systems. This version expands control coverage from 243 to 247 objectives across 18 domains, synchronized with CCM v4.1 for unified cloud and AI governance. A key addition is the Model Security (MDS) domain, featuring 13 AI-specific controls addressing threats like model poisoning, prompt injection, and unauthorized access. AICM v1.1 also updates the AI Consensus Assessment Initiative Questionnaire (AI-CAIQ) to 320 questions and provides comprehensive mappings to major AI governance frameworks, including the EU AI Act, NIST AI RMF, ISO 42001, BSI AIC4, and AIUC-1. These mappings detail alignment and identify where AICM provides operational controls intentionally omitted by risk and regulatory frameworks.

Key takeaway

For Directors of AI/ML or AI Security Engineers navigating complex AI governance and compliance, AICM v1.1 offers a critical, actionable framework. You can use its 247 controls and detailed mappings to operationalize requirements from the EU AI Act, NIST AI RMF, and ISO 42001, filling gaps these frameworks intentionally omit. This allows you to unify cloud and AI security under one system, streamlining compliance and strengthening your organization's AI security posture. Download the package to begin assessing your current security posture.

Key insights

The AICM v1.1 provides a comprehensive, vendor-agnostic framework for securing AI systems and achieving regulatory compliance.

Principles

Method

Organizations can secure AI systems by following a four-step process: SCOPE (identify systems), SELECT (choose controls), IMPLEMENT (apply guidelines), and ASSESS (use AI-CAIQ).

In practice

Topics

Best for: CTO, VP of Engineering/Data, Executive, AI Security Engineer, Director of AI/ML, Legal Professional

Related on AIssential

Open in AIssential →

Editorial summary, takeaway, and curation by AIssential. Original article published by Cloud Security Alliance.