What happened
On August 5, 2026, CSA announced two new initiatives at Black Hat USA 2026: the Catastrophic Risk Annex project, which will develop auditable controls for mitigating catastrophic AI risks by extending CSA's widely-adopted AI Controls Matrix (AICM), and the Frontier-Ready Cybersecurity Resource Center, a centralized hub for frontier-AI security resources. The Catastrophic Risk Annex convenes AI safety, cybersecurity, and national-security professionals to define and validate a concrete set of catastrophic-AI controls, to be tested via pilot audits with real organizations before being folded into AICM.
Why it matters
AICM is one of the most widely referenced AI control catalogues in industry (mapped to by OWASP's own LLM Top 10 2026 and used by many GRC/compliance tooling vendors). A forthcoming extension covering catastrophic/frontier risk controls signals that organizations doing AICM-based compliance mapping will need to plan for an additional control set once piloted controls are finalized.
Action needed
Monitor the Catastrophic Risk Annex working group for draft controls and consider participating in pilot audits; track for eventual incorporation into AICM control mapping programs.