The Coalition for Secure AI (CoSAI) is a global, multi-stakeholder initiative dedicated to advancing the security of AI systems. CoSAI brings together experts from industry, government, & academia to develop practical guidance, promote secure-by-design practices, & close critical gaps in AI system defense. Through its workstreams & open collaboration model, CoSAI supports the responsible development & deployment of AI technologies worldwide.
CoSAI operates under OASIS Open, an international standards & open-source consortium.
coalitionforsecureai.org
Google Donates Secure AI Framework (SAIF) Data to Coalition for Secure AI, Advancing Industry-Wide AI Security Standards
Sept 16, 2025
OASIS Open,
oasis-open.org/ the international open source & standards consortium, announced that Google has donated data from its Secure AI Framework (SAIF)
saif.google/ to the Coalition for Secure AI (CoSAI), an OASIS Open Project. The contribution includes the Coalition for Secure AI Risk Map (CoSAI-RM),
github.com/cosai-oasis/secur… now available as part of CoSAI Tooling. The CoSAI-RM is a framework for identifying, analyzing, & mitigating security risks in AI systems, providing a structured map of the AI security landscape & a common language to address vulnerabilities that traditional software security practices often miss. CoSAI will continuously update, develop, & expand the Risk Map to address emerging threats & evolving security challenges in AI systems.
This contribution strengthens CoSAI’s mission to enhance trust & security in AI development & deployment, directly supporting its 4 Workstreams:
Software Supply Chain Security, Preparing Defenders for a Changing Cybersecurity Landscape, AI Security Risk Governance, & Secure Design Patterns for Agentic Systems.
CoSAI now includes more than 40 industry partners working collaboratively to address AI security challenges.
Premier Sponsors: EY, Google, IBM, Microsoft, NVIDIA, Palo Alto Networks, PayPal, Snyk, Trend Micro, & Zscaler, are leading the way in advancing secure AI practices.
CoSAI’s work is also grounded in the support of its Founding Sponsors: Amazon, Anthropic, Cisco, Cohere, GenLab, Google, IBM, Intel, Microsoft, NVIDIA, OpenAI, PayPal, & Wiz.
OASIS Approves TOSCA V2.0 Standard for Cloud Orchestration
Sept 9, 2025
Members of OASIS Open, the global open source & standards organization, have approved the Topology & Orchestration Specification for Cloud Applications (TOSCA) Version 2.0 as an OASIS Standard,
docs.oasis-open.org/tosca/TO… a status that signifies the highest level of ratification. TOSCA v2.0 marks a significant evolution of the standard, expanding beyond its computing-centric roots to become a universal orchestration language applicable across virtually any domain, from traditional IT infrastructure to IoT deployments, edge computing, & industry-specific automation requirements.
Developed by the OASIS TOSCA Technical Committee (TC),
oasis-open.org/tc-tosca/ TOSCA v2.0 greatly increases the fields of applicability of the standard & marks a fundamental shift in cloud orchestration accessibility. By eliminating the restrictive “Simple Profile” terminology that previously limited the standard to computing environments, TOSCA v2.0 empowers organizations across industries to create & contribute user-defined profiles using terminology specific to their domain & use cases.
The new version expands TOSCA’s technical capabilities w/ user-defined functions for specific operational needs & formal graph traversal syntax that enables more sophisticated relationship modeling. TOSCA v2.0 also introduces a comprehensive operational model for Day 2 service management.
TOSCA v2.0 preserves the core architectural principles that have made the standard successful. It continues to treat both nodes & their relationships as first-class entities w/ full inheritance capabilities, ensuring backward compatibility & maintaining its robust foundation.
oasis-open.org/2025/09/09/oa…