Entries group related changes by the date they shipped. For the commit-level history, see the source repository.
Companion agentic extensions (not a CoSAI v1.0 revision)
Homepage lede now states that autonomy L0 to L5 and override T1 to T5 describe independence and intervention, not a change of owner. Six glossary terms, vendor-risk questions, operating-model enforcement-plane copy, threshold schema optional fields, and AI SAFE² on /compare/ are independently proposed companion material. Register: proposed next-version asks. Not part of CoSAI SRF v1.0.
Whitepaper assessment prompt v2.2
Intake runs before any catalog fetch. The prompt loads slim
principle catalogs, merges extract/map/classify into one pass,
and treats Novel as a map result rather than a catalog-addition
form. A named map-only switch skips citation
registries, live SRF fetch, and draft mechanics.
Changelog.
L5 is the model-artifact supply chain
The L5 subtitle is now Models, Training, Model Supply Chain. Enterprise vendor-risk inventory, tiering, and contracting for all seven vendor categories sit at L1. L5 keeps model cards, signing, BoAIM or SBOM, and vulnerability disclosure, plus a pass-through of that package when a SaaS, agentic, or VAR vendor embeds a model. Public-sector SRF-L5-MON-007 moved to SRF-L1-ACQ-010. Finance and healthcare each gained an L1 vendor register. The security-controls wizard and regulation discovery now assign generic TPRM, HIPAA BAAs, and NYDFS third-party risk to L1.
TSC presentation removed
Removed the May 2026 CoSAI Technical Steering Committee deck from /presentation/. That URL now redirects to the [un]prompted October 2026 deck.
DSGAI identifiers on the threat crosswalk
Added OWASP GenAI Data Security Risks (DSGAI 2026) as a mapping source on threats.json. Nine of the sixteen AI Exchange rows now carry a DSGAI identifier where a one-to-one mapping holds. Fifteen new rows cover DSGAI failures the AI Exchange slug set does not name, including shadow AI, vector-store isolation, over-broad context windows, and telemetry leakage. DSGAI07 and DSGAI08 have no rows: they are a control gap and a compliance outcome, not attack techniques. The file cites DSGAI identifiers and published names; it does not copy DSGAI mitigations.
[un]prompted October 2026 draft deck
Added a 9-slide practitioner deck, Who is responsible for what?, teaching the five CoSAI layers and the security roles that own them, then assigning the speaker’s OpenAI / Hugging Face accountability assessment (obligation, control, one job title), then the IaaS / PaaS / SaaS matrix and where CoSAI sits with OASIS Open and MOSAIC, with a Sessionize packet in view-all. Speaker notes on slides 5 and 6 quote the Article 9, NIS2, CFAA and 800-53 phrases those rows map. Slide 2 notes list facts the 26 August OpenAI technical report added after the LinkedIn draft: the 27 June detection clock, shared Artifactory credentials, WebCache, HDF5 heap over-read, screenshot-service path, pull-based C2, two named CVEs and the 19 July OpenAI-side escalation. Slide 7 walks Identity on each layer: each layer has its own risk, obligation, control, and job title (role, data class, session credential, IdP, model provider not involved). Slide 8 runs architecture, detection, monitoring, incident response, audit, red teaming, and vendor risk across the same five layers. The case study tables are the speaker’s analysis from public disclosures. The deck cites the CoSAI SRF as a published catalog.
Vendor risk categories as structured data
Published the vendor risk assessment as machine-readable vendor-risk.json: seven AI vendor categories with SRF layers, operating models, roles, the vendor-versus-customer accountability split, attestation baseline, and evidence asks, plus risk tiers, cross-cutting risks, and an attestation reference. Registered it in the data index and linked it from llms.txt and the full-text file so agents can fetch the categories without parsing HTML.
Incident response playbooks and GRC exports
Added Day-2 incident response playbooks for seven AI boundary failures, each mapping who leads per operating model. Published the accountability matrix as an OSCAL 1.1.2 catalog and a CSV for GRC ingestion, plus the playbooks as structured JSON.
Vendor risk assessment tool
Added vendor risk assessment for AI suppliers: seven vendor categories mapped to SRF layers with accountability splits and evidence asks, a how-to guide, procurement export templates, and a downloadable XLSX workpaper.
For LLMs and agents
Added a homepage resource hub linking llms.txt, the full-text file, machine-readable data, the knowledge graph, the schema viewer, and the retrieval validation tool. Added this changelog and JSON-LD to the newest pages.
License and integrity
Replaced the LICENSE with verbatim Apache-2.0 text, added a NOTICE, pinned jsPDF 2.5.1, hardened the SRF Stress worker with input validation and an anti-injection guard, added a CI verify workflow, and named OCSF as the evidence schema in the v2.0 governance section.
Machine-readable knowledge layer
Published a glossary registry and per-term API, an ontology graph, a canonical ID registry, an export knowledge pack, and a RAG retrieval validation tool. Added page-level LLM metadata and chunk markers across all pages, plus robots.txt, sitemap, llms-full.txt, a data index, and JSON-LD on every page.
Industry verticals
Added finance, healthcare, insurance, public sector, defense, and manufacturing verticals, each with a hub, controls browser, how-to guide, and workpaper. Renamed the medical vertical to healthcare with redirects, and flagged all vertical schemas experimental.
System prompts
Rebuilt the system instruction pages with live content, all six sector parameters, copy buttons, and a site-aware primer for querying the site with an AI assistant.
CoSAI SRF v1.0 (released May 28, 2026)
Adopted official Section 3 language, added announcement links, removed Draft v0.7 references, and corrected the EU AI Act framing throughout the site and the stress test.
Site restructure
Moved to a seven-item navigation with section hubs and a consolidated framework hub. Added the NICE Cybersecurity Workforce Framework mapping page.
SRF Stress Test
Added a Cloudflare Worker proxy for AI-powered scenario analysis, with model iterations and rendering fixes.
Foundation
Stood up the tools hub with assessment wizards, README, Apache-2.0 license, a security audit, the custom domain, and MITRE ATLAS links on adversarial badges.