A new independent standards body for enterprise AI launched on August 11, 2026. The AI Trust and Security Consortium — AITSC — is a peer-governed initiative capped at 50 security and technology leaders who will collectively build the governance frameworks that most enterprises are still missing.
The founding cohort includes Ulf Mattsson, founder of data security firm Protegrity; Lori Higham, President of Secure Cloud Provider; and Maggie Amato, a CISO and BISO leader formerly of Salesforce and Dell. Applications are now open for the full cohort of 50 — limited to CISOs, CIOs, CTOs, Chief Privacy Officers, and heads of GRC or security architecture who are accountable for AI governance inside their organisations.
Why This Exists
The timing is not accidental. Two data points frame why a consortium like this is needed right now.
McKinsey’s 2026 AI Trust Maturity Survey found that only about one-third of organisations report mature AI governance. And a Linux Foundation study found that 48 percent of organisations now name security concerns as the top barrier to AI adoption — up from 17 percent in 2024.
That gap between AI deployment and AI governance has been widening for two years. Companies are running AI agents across business processes, feeding them sensitive data, and giving them access to customer records, financial systems, and internal communications. The frameworks to govern that responsibly have not kept pace.
AITSC’s founding premise is that the people best positioned to close that gap are practitioners — not vendors with products to sell, and not regulators working from theoretical models. The consortium is designed for security leaders who are already navigating these problems inside real organisations.
What Members Will Build
The consortium is structured around three outputs:
Reference architectures. Practical blueprints for how AI systems should be deployed securely inside enterprise environments — covering data access, model selection, agent scope, and integration points.
Control frameworks. Specific controls that security teams can implement and audit — the kind of granular, operational guidance that board-level risk committees can actually use to measure compliance.
Board-ready governance models. Documentation and reporting structures that let AI governance conversations happen at the executive and board level, without requiring technical expertise from every stakeholder.
Members share real incidents and real vendor performance data under strict confidentiality. The consortium is explicitly not a vendor showcase — participation is limited to practitioners, and the output is designed for practitioners.
What This Means for Business
For any business currently deploying or evaluating enterprise AI, the AITSC launch is a signal worth paying attention to.
The governance gap is a real risk. The Linux Foundation’s 48 percent figure reflects genuine concern, not theoretical caution. When AI agents have access to sensitive business data and can take actions across systems, the security and governance architecture around them matters in ways that generic IT security frameworks do not fully address.
Regulation is coming regardless. The EU AI Act’s high-risk provisions became enforceable August 2, 2026. The US is debating its own frameworks. Waiting for a vendor to solve governance for you is no longer a viable strategy for enterprise AI programs.
Peer-defined standards carry more weight. Frameworks built by practitioners who are accountable for real-world AI deployments are more useful than compliance checklists produced by consultancies or policy bodies without operational skin in the game. When AITSC publishes reference architectures, they will reflect how enterprise AI actually works — not how it is supposed to work in a procurement brochure.
Third-party governance scrutiny is increasing. If your business uses AI agents and works with enterprise clients, expect them to start asking about your governance posture in ways they have not before. Having answers — and ideally frameworks aligned with emerging standards like AITSC — will matter for enterprise sales conversations in 2026 and beyond.
The Broader Context
AITSC sits inside a broader shift toward practitioner-led AI governance. The EU has its frameworks, the US has its executive orders, and the Linux Foundation’s agentic AI alliance has set some technical standards. But none of those address the operational reality of what it looks like to govern AI agents inside a complex enterprise environment with real incident history and real vendor performance data.
That is the gap AITSC is designed to fill. Whether it succeeds depends on who joins the cohort and whether the output translates into frameworks that practitioners actually use. The founding team has the credibility. The structure — peer-governed, confidential, practitioner-only — is designed correctly.
For enterprise AI programs that have been building deployments faster than governance, this is the moment to close that gap. The question is no longer whether governance frameworks will be required. It is whether your organisation builds them before or after a problem forces the issue.
Enterprise DNA works with businesses to design AI agent systems that are built for real deployment — including the governance, security, and oversight that enterprise AI requires. Start a conversation about your AI program.
Source
PR Newswire