Skip to content
@cosai-oasis

Coalition for Secure AI (CoSAI)

The mission of CoSAI is to enhance trust and security in AI development and deployment through collaborative innovation and standardization.

Welcome to the Coalition for Secure AI (CoSAI)

CoSAI is an OASIS Open Project and is an open ecosystem of AI and security experts from industry leading organizations dedicated to sharing best practices for secure AI deployment and collaborating on AI security research and product development.

For more information about CoSAI, visit our project website.

To learn more about how this Open Source project is governed, who our sponsors are, and who is serving on our Project Governing Board and Technical Steering Committee, check out the OASIS Open Project repository. If you want to start contributing to CoSAI, please see our onboarding information for new contributors.

CoSAI AI Security Guidance Publications

CoSAI Workstreams

CoSAI will address key AI security issues through several critical workstreams in collaboration with industry and academia, including efforts such as:

Workstream 1: Software Supply Chain Security for AI systems

This workstream focuses on enhancing AI security by addressing the challenges of third-party model risks, provenance, and AI application security. It builds upon widely recognized security frameworks like the SSDF and SLSA, extending them for AI development. Link to workstream 1 GitHub repository

Workstream 2: Preparing Defenders for a Changing Cybersecurity Landscape

The goal of this workstream is to develop a defender’s framework to identify needed investments to address the security impacts of AI use by business applications, attackers, and defenders as well as mitigations techniques and best practices. The Defender’s framework aims to scale investments and mitigation strategies with the emergence of pivotal offensive cybersecurity advancements in AI models. Link to workstream 2 GitHub repository

Workstream 3: AI Security Risk Governance

Workstream 3 contributors are working to develop a security-focused risk and controls taxonomy, checklist, and scorecard to guide practitioners in readiness assessments, management, monitoring, and reporting of their AI products, services, and components. Link to workstream 3 GitHub repository

Workstream 4: Secure Design Patterns for Agentic Systems Workstream

The goal of this workstream is to research and develop secure design patterns for AI-based agentic systems including updates to AI usage threat models, conceptual high-level secure design pattern(s), impacts to secure infrastructure design, and other agent integration and use based needs. Link to workstream 4 GitHub repository

Support CoSAI as a sponsor

Technical participation is free and open to all developers. That’s why CoSAI relies on a core group of stakeholder organizations whose financial commitment ensures that the initiative stays on track and receives the resources it needs to succeed. Learn more about the benefits of becoming a member of the Coalition for Secure AI here.

Pinned Loading

  1. ws1-supply-chain ws1-supply-chain Public

    Repository for CoSAI Workstream 1, Software Supply Chain Security for AI Systems

    41 6

  2. ws2-defenders ws2-defenders Public

    Repository for CoSAI workstream 2, Preparing Defenders for a Changing Cybersecurity Landscape

    47 32

  3. ws4-secure-design-agentic-systems ws4-secure-design-agentic-systems Public

    Repository for CoSAI Workstream 4, Secure Design Patterns for Agentic Systems

    85 24

  4. ws3-ai-risk-governance ws3-ai-risk-governance Public

    Repository for CoSAI workstream 3, AI Risk Governance

    21 2

  5. oasis-open-project oasis-open-project Public

    This repository is for administrative documents for the CoSAI OASIS Open Project

    73 10

  6. secure-ai-tooling secure-ai-tooling Public

    The CoSAI Risk Map is a framework for identifying, analyzing, and mitigating security risks in Artificial Intelligence systems. As traditional software security practices are not always sufficient …

    Python 57 17

Repositories

Showing 10 of 10 repositories
  • secure-ai-tooling Public

    The CoSAI Risk Map is a framework for identifying, analyzing, and mitigating security risks in Artificial Intelligence systems. As traditional software security practices are not always sufficient for AI, this project provides a shared understanding and a common language for addressing the unique security challenges of the AI development lifecycle.

    cosai-oasis/secure-ai-tooling’s past year of commit activity
    Python 57 Apache-2.0 17 14 1 Updated Feb 12, 2026
  • ws4-secure-design-agentic-systems Public

    Repository for CoSAI Workstream 4, Secure Design Patterns for Agentic Systems

    cosai-oasis/ws4-secure-design-agentic-systems’s past year of commit activity
    85 24 21 3 Updated Feb 12, 2026
  • cosai-tsc Public

    Repository for the work of the CoSAI Technical Steering Committee (TSC)

    cosai-oasis/cosai-tsc’s past year of commit activity
    18 4 1 1 Updated Feb 11, 2026
  • oasis-open-project Public

    This repository is for administrative documents for the CoSAI OASIS Open Project

    cosai-oasis/oasis-open-project’s past year of commit activity
    73 10 0 0 Updated Feb 11, 2026
  • project-codeguard Public

    Project CodeGuard is an open-source, model-agnostic security framework that embeds secure-by-default practices into AI coding agent workflows. It provides comprehensive security rules that guide AI assistants to generate more secure code automatically.

    cosai-oasis/project-codeguard’s past year of commit activity
    Python 45 5 3 1 Updated Feb 9, 2026
  • ws3-ai-risk-governance Public

    Repository for CoSAI workstream 3, AI Risk Governance

    cosai-oasis/ws3-ai-risk-governance’s past year of commit activity
    21 2 6 0 Updated Feb 4, 2026
  • .github Public
    cosai-oasis/.github’s past year of commit activity
    1 1 0 0 Updated Jan 12, 2026
  • ws2-defenders Public

    Repository for CoSAI workstream 2, Preparing Defenders for a Changing Cybersecurity Landscape

    cosai-oasis/ws2-defenders’s past year of commit activity
    47 Apache-2.0 32 11 3 Updated Dec 2, 2025
  • ws1-supply-chain Public

    Repository for CoSAI Workstream 1, Software Supply Chain Security for AI Systems

    cosai-oasis/ws1-supply-chain’s past year of commit activity
    41 6 9 (3 issues need help) 1 Updated Sep 29, 2025
  • resources Public
    cosai-oasis/resources’s past year of commit activity
    3 1 0 0 Updated Jun 12, 2025

People

This organization has no public members. You must be a member to see who’s a part of this organization.

Top languages

Loading…

Most used topics

Loading…