
Between April and August 2026, at least six distinct AI-security efforts launched across North America, Europe, and Asia, several in the same week as one another and some for contradictory reasons. This piece maps 18 of them: what each says it's trying to achieve, who founded and backs it, and what it has actually shipped versus only announced.
Two patterns stand out once they're all laid side by side. First, a small number of organizations, chiefly Google, Microsoft, and Anthropic, sit inside a large share of these efforts simultaneously. Second, agentic AI security is being worked on independently by seven different initiatives across five institutional categories, with no visible coordination between most of them, a pattern likely to produce incompatible standards rather than a converged one unless something changes.
I've tracked eighteen initiatives across a dozen countries, five months, and several issues being worked seven times over. This post dives into what exists, who's behind it, and what's actually been produced so far. Plus a few recommendations on how we might better leverage these efforts
A Landscape Assembled in Weeks, Not Years
Ask what "AI security" means as an institutional matter, and the honest answer is that it's hard to know without a map, which is made all the more difficult as the map keeps changing while it's being drawn. Consider the last four months alone:
Apr 7–8 | Anthropic launches Project Glasswing (AI-driven vulnerability scanning) and the AI Alliance launches Project Tapestry (open, federated model training) in the same week, one about deploying a powerful closed model defensively, the other about preventing frontier AI from concentrating in a few firms at all. |
Jun 2 | Executive Order 14409 creates Gold Eagle, a federal vulnerability clearinghouse. |
Jul 7 |
|
Jul 14 |
|
Jul 27 | Microsoft announces EXTRA (an external red-teaming alliance) and NVIDIA launches the Open Secure AI Alliance (37–52 members) on the same day, both explicit responses to the same underlying critique: that AI safety testing has been too internally-oriented. |
Aug 5 | JPMorgan CEO Jamie Dimon personally expands the Alliance for Critical Infrastructure, a cross-sector resilience coalition founded in February, to make AI risk its top priority, recruiting 40+ companies across banking, energy, water, and transportation. |
Who's actually showing up
Bar length = number of tracked initiatives. Segment color = category. Click a row for full detail, including caveats about nested work streams or weaker evidence of participation.
Google (10) and Microsoft (10) lead this chart, with Anthropic (8) close behind, and their presence spans nearly every category tracked here. That's worth noting on its own: these are also the companies operating the frontier models most of this apparatus exists to secure, so their repeated presence isn't surprising. But it's worth being careful about what that leadership does and doesn't imply for the landscape as a whole. In some of the older, more established efforts (CoSAI, the Frontier Model Forum), the same handful of companies genuinely do reappear across the roster. In others, the picture is different: the Open Secure AI Alliance excludes Google, OpenAI, and Anthropic and has participation from over 100 other companies; Singapore's AI Verify Foundation counts over 50 general members spanning cloud providers, enterprise software firms, and a bank. And for several of the newest entries, Gold Eagle, Microsoft EXTRA, the NIST Agent Standards Initiative, and the Alliance for Critical Infrastructure's AI pivot, no public roster exists yet, so it's genuinely too early to say how broad or narrow participation will turn out to be. The fair summary is that a few companies lead often, not that they're the only ones present.
What Each Effort is Actually Trying To Do
This is the core of the map: for each initiative, what it says its goal is, who founded and backs it, and, critically, what it has actually produced so far, as distinct from what it has announced. Deliverable status is marked with a simple tag. Shipped means there's a concrete, citable artifact (a published framework, a released tool, an operating benchmark). Early stage means the initiative has launched but hasn't yet produced its core output. Opaque means it's operating but hasn't published enough for an outside observer to tell. Dormant means it launched with real fanfare but appears not to have produced anything publicly verifiable in over a year, distinct from "opaque" because there's enough history here to actually judge, not just a gap in information.
Using AI to defend infrastructure directly
Three efforts built around defending infrastructure at scale, two using AI itself as the defensive tool and one built on cross-sector industry coordination that has just added AI to its mandate.
Securing AI systems: standards and best practices
Six efforts building shared frameworks, benchmarks, and controls for AI-specific risks rather than each organization solving them independently.
Government & multilateral coordination
Four efforts where public authority, rather than industry membership, is the organizing mechanism, including one operating on fundamentally different terms than the rest.
One more entry belongs in this section, but on different terms than the rest: everything above either has direct private-sector membership or was built with the explicit goal of eventual interoperability with other countries' efforts. China's AI security standards program has neither. It's developed entirely through domestic state standards machinery, its drafting participants are Chinese enterprises and research institutes rather than the multinational membership seen elsewhere in this piece, and there is no meaningful channel, formal or informal, connecting it to the other government-led efforts above. It's included because it's addressing the identical technical problem as several of them, on a strikingly similar timeline, entirely independently.
Also worth knowing
India stood up its own IndiaAI Safety Institute in January 2025, using a hub-and-spoke model connecting government, academic, and private-sector partners, outside the original 11-country Seoul Statement network, explicitly aimed at bringing Global South priorities (local-language benchmarking, resource-constrained deployment contexts) into a conversation otherwise dominated by the US, UK, and EU.
Open-source tooling & democratized defense
Three efforts betting that open, inspectable tools, not just closed vendor products, are essential to real defensive capability.
Information sharing & red-teaming collaboratives
Two efforts focused on operational intelligence flow and testing capacity rather than published frameworks.
Before the specific entries: this category is colliding with a much older institutional model. Information Sharing and Analysis Centers (ISACs) date to a 1998 presidential directive. Each critical-infrastructure sector gets a trusted channel for sharing threat intelligence with government and each other, coordinated loosely through the National Council of ISACs (NCI). Existing sector ISACs are already folding AI threats into their normal work, though not without friction. One sector ISAC's leadership has publicly voiced skepticism about even using AI to process shared threat data, over concerns it could break the trust chain that makes information-sharing work at all. Meanwhile, the federal government has directed a technology-specific AI-ISAC into existence, the first ISAC ever organized around a technology rather than a sector, which may be part of why it remains stalled, while the existing IT-ISAC has publicly argued a new one is unnecessary duplication.
A note excluded from the list
Project Tapestry, the AI Alliance's federated open-model training effort (launched Apr 2026, with Yann LeCun as Chief Science Advisor), is mentioned earlier in this piece but isn't counted as a tracked security initiative. It's a genuine, well-backed effort. The AI Alliance, IBM, and Meta are real participants, and it has an actual technical roadmap, but its goal is preventing frontier AI from concentrating in a few firms or countries, not cyber-defense or model safety. It gets discussed alongside security initiatives constantly, because its backers invoke national-security framing (avoiding dependence on Chinese open-weight models), but including it in the same count as CoSAI or Project Glasswing would blur what this piece is actually trying to track.
What Subjects Are Actually Getting Attention
A different, and arguably more useful, question than "who's involved" is "what problem is getting solved, and how many times over." The map below treats each subject area as a circle sized by how many of the 18 tracked initiatives address it; circles that share initiatives are pulled together and overlap, so clustering itself is the signal.
Where the effort is actually going
Each circle is a subject area, sized by how many initiatives address it. Circles that share initiatives are pulled together and overlap. Click any circle for the initiatives behind it and its closest overlapping subjects.
Agentic AI security and model/system security standards are now tied as the most contested subjects in the landscape, each touched by 7 of 18 tracked initiatives. Six of the seven agentic-security efforts, CoSAI, OWASP, MLCommons, CSA, NIST's Agent Standards Initiative, and OSAA, sit within the same broadly Western, industry-and-government ecosystem tracked throughout this piece, with real (if unrealized) potential to converge, since several already share corporate backers. That's the opposite of a coverage gap. It's a coordination gap, and coordination gaps around technical standards have a specific failure mode: incompatible protocols that lock in before anyone reconciles them. The seventh, China's TC260, is a different case, not because it's unreachable diplomatically, but because of who's actually in the room drafting it: its standards are written by domestic Chinese enterprises and research institutes convened through state-organized technical working groups, not the kind of open, multinational corporate membership that defines CoSAI, OSAA, or AI Verify.
At the other extreme, one subject sits completely isolated with zero connection to anything else in the dataset: trust & safety / content moderation, addressed only by ROOST. Two subjects that draw a lot of public concern, CBRN/catastrophic risk and certification & compliance, are each only being worked on by two or three initiatives, meaning most of what currently exists in AI safety governance is voluntary and self-reported rather than independently audited.
What This Adds Up To
Groups should clearly articulate intended objectives, outcomes, and coordination channels between efforts
In order to avoid duplication between groups, each initiative should externally assert what challenges they are seeking to address and how they intend to achieve these objectives. This wouldn't limit each initiative from pursuing the same objective, as each could do so in a unique way, such as reference architectures, case studes, policy recommendations, etc. It should also be made clear how each initative intends to work with each other. This may not be possible for every effort, especially given the rate of change in this space, but at the very least, companies engaged in several initatives could outline how each engagement seeks to contribute toward a collective vision on AI security.
The two organizations both calling themselves "AI-ISAC" need to reconcile rather than compete.
One is an operating nonprofit that predates the other by roughly 18 months; the other is a federally-directed effort that hasn't launched. A joint working arrangement, or at minimum a public memorandum clarifying scope and avoiding brand collision, would prevent members and threat-intel contributors from having to guess which "AI-ISAC" they should be talking to.
Coordinate the six initiatives working on agentic AI security to converge on a joint industry position before their standards harden.
CoSAI, OWASP, MLCommons, CSA, NIST's Agent Standards Initiative, and OSAA are each building agent-identity and authorization work independently, across four institutional categories, with no shared working group connecting them, despite several already sharing corporate supporters. A government convener isn't obviously the right answer here: NIST's own standards process, built for deliberate multi-year consensus-building, is already struggling to keep pace with how fast agentic architectures are shipping and changing. A better fit would be an industry-led coordinating body: not a new standards-setter competing with the six, but a lightweight function whose only job is tracking who's working on what, flagging duplication early, and making sure each initiative is actually adding distinct value rather than re-solving a problem another has already covered. That's a lower bar than technical convergence, and achievable faster than waiting on any single government process to catch up.
Inventorying this landscape was the necessary first step, and the clearest opportunity it surfaced is coordination, not consolidation. These initiatives don't need to merge into one body, and several are genuinely doing different things well. What's missing is a lightweight mechanism: a shared registry, a standing liaison, an industry-run coordinating body, that lets initiatives working on the same problem compare notes before they've each locked in their own answer.
There's a second-order use for that kind of synthesis worth naming directly. NIST's Agent Standards Initiative, the UK's AI Security Institute, and the EU's Action Plan on Cybersecurity and AI are each, in their own way, trying to build durable government standards on a timeline that struggles to keep pace with how fast the underlying technology moves. A synthesized view of what CoSAI, OWASP, MLCommons, CSA, and OSAA have already tested against real deployments, where they agree, where they've each solved the same problem differently, and where gaps remain unaddressed by anyone, is exactly the kind of pre-competitive groundwork that formal standards processes are usually built to absorb rather than originate. Treated that way, the accumulated output of these industry efforts could function as a runway: not a substitute for NIST, UK, or EU standards, but a running head start that lets those processes formalize what's already been tried rather than starting from first principles each time. That only works if someone is actually doing the synthesis, which circles back to the coordination gap this piece keeps finding. Right now, nobody has that job.
All ArticlesRelated blog posts

The Identity Surface You're Not Watching: Three Layers of Coding Agent Risk
There's a widespread assumption in enterprise security that identity is a problem IAM programs know how to solve....

A Safer Future with Agents
We built agents to act on their own. We're somehow surprised when they do. Two weeks ago, OpenAI ran a cyber eval...

The Coding Agent Attack Surface Needs More Than Posture Checks
Coding agents have a misconfiguration problem. YOLO mode enabled to reduce approval friction, sandbox enforcement...
Secure Your Agents
We’d love to chat with you about how your team can secure and govern AI Agents everywhere.
Get a Demo