AI Controls Matrix v1.1: Strengthening the Foundation for Trustworthy AI
Summary
The Cloud Security Alliance (CSA) released the AI Controls Matrix (AICM) v1.1 on July 14, 2026, a significant update to its framework for secure and trustworthy AI systems. This version expands control coverage from 243 to 247 objectives across 18 domains, synchronized with CCM v4.1 for unified cloud and AI governance. A key addition is the Model Security (MDS) domain, featuring 13 AI-specific controls addressing threats like model poisoning, prompt injection, and unauthorized access. AICM v1.1 also updates the AI Consensus Assessment Initiative Questionnaire (AI-CAIQ) to 320 questions and provides comprehensive mappings to major AI governance frameworks, including the EU AI Act, NIST AI RMF, ISO 42001, BSI AIC4, and AIUC-1. These mappings detail alignment and identify where AICM provides operational controls intentionally omitted by risk and regulatory frameworks.
Key takeaway
For Directors of AI/ML or AI Security Engineers navigating complex AI governance and compliance, AICM v1.1 offers a critical, actionable framework. You can use its 247 controls and detailed mappings to operationalize requirements from the EU AI Act, NIST AI RMF, and ISO 42001, filling gaps these frameworks intentionally omit. This allows you to unify cloud and AI security under one system, streamlining compliance and strengthening your organization's AI security posture. Download the package to begin assessing your current security posture.
Key insights
The AICM v1.1 provides a comprehensive, vendor-agnostic framework for securing AI systems and achieving regulatory compliance.
Principles
- Unified governance for cloud and AI systems.
- Operationalize AI governance requirements.
- Bridge gaps in risk and regulatory frameworks.
Method
Organizations can secure AI systems by following a four-step process: SCOPE (identify systems), SELECT (choose controls), IMPLEMENT (apply guidelines), and ASSESS (use AI-CAIQ).
In practice
- Use AICM's 247 controls for ISO 42001 certification.
- Extend existing CCM implementations to cover AI systems.
- Address EU AI Act operational security gaps.
Topics
- AI Governance
- AI Security Controls
- Cloud Security Alliance
- Model Security
- EU AI Act Compliance
- NIST AI RMF
Best for: CTO, VP of Engineering/Data, Executive, AI Security Engineer, Director of AI/ML, Legal Professional
Related on AIssential
See Counsel's argued verdicts on the open AI decisions leaders are weighing →
Editorial summary, takeaway, and curation by AIssential. Original article published by Cloud Security Alliance.