We publish the AI security research the rest of the market cites six months later.
The home for CSI's AI security research and intelligence: flagship reports, weekly threat briefs, governance frameworks, and the practical guides and assessment templates we use in the field. Everything in one place, structured to be found — by you and by the agents you ask. For the full searchable archive of every published post, open CSI Intelligence.
The analysis we put our name on.
The Five Eyes AI Security Gap: 10 Controls the Alliance Missed
A gap analysis against joint five-nation guidance — and the controls an adversary reaches for first.
Read the report →CVSS Is Mathematically Obsolete — We Ran the Formula
The before/after math showing how CVSS misranks the risk that actually gets you breached.
Read the report →Hermes Sovereign Runtime: 4 Criticals & 3 CVEs Before Production
The find-file-fix-verify process that put an agent runtime through security before launch — in public.
Read the report →New intelligence, published every Monday.
Browse every published article, brief, and annual report.
The full archive is searchable and tag-filtered across five streams: AI & Agents, Threats & Risks, Annual Intelligence, Frameworks & Standards, and Engineered Defense.
Human-in-the-loop is a scaling failure — and the market just agreed
Read the full analysis →The MCP flaw is a design decision, not a bug — contain it now
Read the full analysis →What a public MCP scan can't see: the trust-boundary audit
Read the full analysis →Subscribe to Cyber Weekly Intelligence
One sharp brief, delivered every Monday morning. No noise.
The models we operate by — and publish openly.
These are not separate products. They are one architecture with one intended outcome: engineered certainty — the ability to prove what your systems and agents can and cannot do, before something goes wrong rather than after.
Engineered Certainty
Prevention, not detection. Certainty is engineered when every execution boundary is enforced deterministically and every consequential action is provable — not inferred from logs after the fact. Every framework below is a layer of that argument.
Digital Shield
The five-layer Zero Trust prevention model — L1 kernel through L5 human — that every CSI system implements.
See the architecture →AI SAFE² v3.0
161 controls across five pillars plus CP.1–CP.10 Cross-Pillar Governance, crosswalked to 32+ frameworks.
Explore the framework →NEXUS-A2A Protocol
Agent-to-agent accountability — cryptographic identity, monotonic delegation, and a governed memory boundary.
Read the protocol →Cognitive Sovereignty v2.0
When AI mediates your decisions, who owns them? The L5 human layer of Digital Shield, and the controls that hold it.
Explore the doctrine →CryptoSHIELD
Cryptographic trust and identity protection — containment for keys, wallets, and treasury operations before the drainer runs.
Explore the framework →MITRE ATT&CK for AI Systems
The adversary-technique knowledge base, mapped to AI SAFE² controls — the evidence behind prevention-first engineering.
Read the mapping →Practical, field-tested, and free to download.
About the research and intelligence.
Is the research free to read?+
Yes. Our flagship reports, weekly intelligence archive, frameworks, and reference material are openly readable. Some downloadable guides and templates ask for a work email so we can send updates.
How often is new AI security research intelligence published?+
The Cyber Weekly Intelligence brief ships every Monday morning. Flagship reports and framework updates publish as the research warrants — over 75 publications to date, read in 47 countries.
Where is the full archive of CSI articles?+
CSI Intelligence at cyberstrategyinstitute.com/blog/ is the live library — every published article, brief, and annual report, searchable and filterable by tag across five streams. This Research Hub is the curated entry point: flagship reports, the frameworks and doctrine we publish, and the downloadable guides and templates.
What frameworks does CSI publish?+
Six: Digital Shield (the five-layer prevention architecture), AI SAFE² v3.0 (AI governance, 161 controls), the NEXUS-A2A Protocol (agent-to-agent trust), the Cognitive Sovereignty Framework v2.0 (the human layer), CryptoSHIELD (cryptographic trust and identity protection), and our MITRE ATT&CK mapping for AI systems. They are layers of one architecture whose intended outcome is engineered certainty.
Can I cite or share your research?+
Please do — with attribution. Everything is dated and verifiable so you can reference the original publication. If you need the underlying methodology for a formal citation, contact us.
Read the research first. Meet the risk second.
Get the weekly brief, or talk to the team behind the research about your environment.