Perspective · for the CISO
Stand up an AI Security CoE, without it becoming shelf-ware.
Every function is adopting AI on its own terms, and “buy a platform” doesn’t build the capability or the culture. An AI Security & Safety Center of Excellence centralises the governance, prevents Shadow AI, and builds the AI-first way of working — if it’s structured to deliver, not to produce decks.
A federated model: one control spine and one culture at the centre, delivery owned at the edge.
The trap to avoid
A CoE that owns everything becomes a bottleneck; one that owns nothing becomes a newsletter. The build has to centralise the spine and the standard while pushing delivery to the functions.
“How do I build an AI Security CoE that actually ships capability — and then operate it?”
The answer
Anchor the whole CoE on one control spine.
The CoE is built on the CSA AI Controls Matrix — 247 objectives across 18 domains — as the master spine every skill, assessment, and maturity claim attaches to. Sequenced from the SOC, measured honestly, governed by control coverage and the autonomy gate. Because ~85% of AICM controls extend existing cloud controls, this is faster than it looks.
This document is what you build and why. For how to operate it — by move, by lens, and by role — see the companion operating guide.
The assembly kit
Twelve modules: assemble the case you need.
Pick and choose to build the pitch for your board, your functions, and your auditors. Each module is a self-contained piece of the case.