The Cloud Security Alliance AI Safety Initiative (CSAI) has advanced Autonomous Action Runtime Management (AARM), an open specification for governing AI-agent tool use at the point of execution. Originally contributed by Vanta, AARM treats upstream controls—such as prompt-injection defenses, retrieval security, orchestration hardening, memory protection, and identity controls—as necessary but insufficient when models reason over mixed trusted and untrusted context.
AARM intercepts proposed tool invocations and evaluates contextual policy and authorization before an agent can act, enabling actions to be approved, denied, or deferred for human review while producing tamper-evident audit records. The vendor-neutral initiative is supported by a CSA working group with participants including Elastic, Darktrace, Truist, Gusto, Ballistic Ventures, and IEEE, seeking interoperable runtime-security requirements before proprietary agent-security designs fragment the market.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
The article author agreed to co-chair the CSA AARM initiative with Herman Errico, Akul Loomba, and Chris Hughes. The working group includes representatives from Elastic, Darktrace, Truist, Gusto, Ballistic Ventures, and IEEE.
Vanta contributed the AARM specification to the CSAI Foundation under vendor-neutral Cloud Security Alliance governance.
The Autonomous Action Runtime Management (AARM) system specification for securing AI-driven actions at runtime was published as an arXiv paper.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
noma.security
Open sourcearxiv.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.