Project

Changelog

What changed on this site and when, tied to CoSAI AI Shared Responsibility Framework releases. Dates are the date the change went live.

Status and cadence. This site tracks CoSAI SRF v1.0 (released May 28, 2026) and previews v2.0 work in progress. The core framework reference follows official CoSAI and OASIS releases. Industry vertical schemas are independently proposed extensions, flagged experimental, and are not part of the official CoSAI release.

Entries group related changes by the date they shipped. For the commit-level history, see the source repository.

September 2026
Update

Companion agentic extensions (not a CoSAI v1.0 revision)

Homepage lede now states that autonomy L0 to L5 and override T1 to T5 describe independence and intervention, not a change of owner. Six glossary terms, vendor-risk questions, operating-model enforcement-plane copy, threshold schema optional fields, and AI SAFE² on /compare/ are independently proposed companion material. Register: proposed next-version asks. Not part of CoSAI SRF v1.0.

Whitepaper assessment prompt v2.2

Intake runs before any catalog fetch. The prompt loads slim principle catalogs, merges extract/map/classify into one pass, and treats Novel as a map result rather than a catalog-addition form. A named map-only switch skips citation registries, live SRF fetch, and draft mechanics. Changelog.

L5 is the model-artifact supply chain

The L5 subtitle is now Models, Training, Model Supply Chain. Enterprise vendor-risk inventory, tiering, and contracting for all seven vendor categories sit at L1. L5 keeps model cards, signing, BoAIM or SBOM, and vulnerability disclosure, plus a pass-through of that package when a SaaS, agentic, or VAR vendor embeds a model. Public-sector SRF-L5-MON-007 moved to SRF-L1-ACQ-010. Finance and healthcare each gained an L1 vendor register. The security-controls wizard and regulation discovery now assign generic TPRM, HIPAA BAAs, and NYDFS third-party risk to L1.

August 2026
Update

TSC presentation removed

Removed the May 2026 CoSAI Technical Steering Committee deck from /presentation/. That URL now redirects to the [un]prompted October 2026 deck.

DSGAI identifiers on the threat crosswalk

Added OWASP GenAI Data Security Risks (DSGAI 2026) as a mapping source on threats.json. Nine of the sixteen AI Exchange rows now carry a DSGAI identifier where a one-to-one mapping holds. Fifteen new rows cover DSGAI failures the AI Exchange slug set does not name, including shadow AI, vector-store isolation, over-broad context windows, and telemetry leakage. DSGAI07 and DSGAI08 have no rows: they are a control gap and a compliance outcome, not attack techniques. The file cites DSGAI identifiers and published names; it does not copy DSGAI mitigations.

[un]prompted October 2026 draft deck

Added a 9-slide practitioner deck, Who is responsible for what?, teaching the five CoSAI layers and the security roles that own them, then assigning the speaker’s OpenAI / Hugging Face accountability assessment (obligation, control, one job title), then the IaaS / PaaS / SaaS matrix and where CoSAI sits with OASIS Open and MOSAIC, with a Sessionize packet in view-all. Speaker notes on slides 5 and 6 quote the Article 9, NIS2, CFAA and 800-53 phrases those rows map. Slide 2 notes list facts the 26 August OpenAI technical report added after the LinkedIn draft: the 27 June detection clock, shared Artifactory credentials, WebCache, HDF5 heap over-read, screenshot-service path, pull-based C2, two named CVEs and the 19 July OpenAI-side escalation. Slide 7 walks Identity on each layer: each layer has its own risk, obligation, control, and job title (role, data class, session credential, IdP, model provider not involved). Slide 8 runs architecture, detection, monitoring, incident response, audit, red teaming, and vendor risk across the same five layers. The case study tables are the speaker’s analysis from public disclosures. The deck cites the CoSAI SRF as a published catalog.

June 2026
Update

Vendor risk categories as structured data

Published the vendor risk assessment as machine-readable vendor-risk.json: seven AI vendor categories with SRF layers, operating models, roles, the vendor-versus-customer accountability split, attestation baseline, and evidence asks, plus risk tiers, cross-cutting risks, and an attestation reference. Registered it in the data index and linked it from llms.txt and the full-text file so agents can fetch the categories without parsing HTML.

Incident response playbooks and GRC exports

Added Day-2 incident response playbooks for seven AI boundary failures, each mapping who leads per operating model. Published the accountability matrix as an OSCAL 1.1.2 catalog and a CSV for GRC ingestion, plus the playbooks as structured JSON.

Vendor risk assessment tool

Added vendor risk assessment for AI suppliers: seven vendor categories mapped to SRF layers with accountability splits and evidence asks, a how-to guide, procurement export templates, and a downloadable XLSX workpaper.

For LLMs and agents

Added a homepage resource hub linking llms.txt, the full-text file, machine-readable data, the knowledge graph, the schema viewer, and the retrieval validation tool. Added this changelog and JSON-LD to the newest pages.

License and integrity

Replaced the LICENSE with verbatim Apache-2.0 text, added a NOTICE, pinned jsPDF 2.5.1, hardened the SRF Stress worker with input validation and an anti-injection guard, added a CI verify workflow, and named OCSF as the evidence schema in the v2.0 governance section.

Machine-readable knowledge layer

Published a glossary registry and per-term API, an ontology graph, a canonical ID registry, an export knowledge pack, and a RAG retrieval validation tool. Added page-level LLM metadata and chunk markers across all pages, plus robots.txt, sitemap, llms-full.txt, a data index, and JSON-LD on every page.

Industry verticals

Added finance, healthcare, insurance, public sector, defense, and manufacturing verticals, each with a hub, controls browser, how-to guide, and workpaper. Renamed the medical vertical to healthcare with redirects, and flagged all vertical schemas experimental.

System prompts

Rebuilt the system instruction pages with live content, all six sector parameters, copy buttons, and a site-aware primer for querying the site with an AI assistant.

May 2026
v1.0 release

CoSAI SRF v1.0 (released May 28, 2026)

Adopted official Section 3 language, added announcement links, removed Draft v0.7 references, and corrected the EU AI Act framing throughout the site and the stress test.

Site restructure

Moved to a seven-item navigation with section hubs and a consolidated framework hub. Added the NICE Cybersecurity Workforce Framework mapping page.

SRF Stress Test

Added a Cloudflare Worker proxy for AI-powered scenario analysis, with model iterations and rendering fixes.

Foundation

Stood up the tools hub with assessment wizards, README, Apache-2.0 license, a security audit, the custom domain, and MITRE ATLAS links on adversarial badges.