- AI trust scoring and the CSA risk rubric
Quick recap. Rohit Valia from Tumeryk presented on AI trust scoring and the Cloud Security Alliance's new risk rubric for AI. Rohit explained Tumeryk's platform for evaluating AI models across six pillars: security, privacy, reliability, excessive agency, transparency, and safety and societal impact. He demonstrated how the platform generates real-time trust scores for different AI models including Claude, Gemini, and OpenAI's models, showing that Gemini generally performed best across most categories. The discussion included a detailed explanation of how prompts should remain within organizational boundaries to protect IP, and Rohit showed the platform's capabilities for monitoring and controlling AI agent interactions. After the presentation, participants discussed the recent OpenAI and Hugging Face security incident, with many expressing skepticism about the details provided and questioning the motivations behind the public disclosure.
Show 4 discussion topics
AI Trust Scoring Framework Presentation
Rohit Valia from Tumeryk presented on their AI trust scoring framework, which evaluates AI models across six pillars: security, privacy, reliability, excessive agency, transparency, and safety/societal impact. The framework, developed in partnership with the Cloud Security Alliance, provides trust scores for various AI models including Gemini, Claude, and others, with Gemini showing the strongest performance across most categories. Rohit demonstrated how organizations can use Tumeryk's platform to implement enterprise controls for AI usage, including guardrails, topic restrictions, and sensitive data filtering to keep prompts and outputs within organizational boundaries. The platform also provides visibility into model usage across the enterprise and enables sanctioned model lists for approved AI usage.
Browser Security Solutions Presentation
Rohit presented on browser security solutions, explaining their desktop agents and browser extensions that monitor and review AI prompts before execution to prevent unauthorized actions. Stryker asked about handling skills in the new browser, and Rohit described their plans to evaluate skills through desktop agents and soon-to-be-released containerized agents with defined network and process controls. After the presentation, several new and existing members introduced themselves, including JD who shared his background in cloud security and his recent transition to freelance work. The group also discussed recent news about OpenAI and Hugging Face's security incident, with participants expressing skepticism about the lack of detailed information and concerns about the security controls in place.
AI Security Practices Discussion
Members shared critical views of how the major AI labs, Anthropic and OpenAI among them, are handling security. The view from several attendees was that these companies hire well-known security people but do not visibly translate that into controls, and that the public messaging leans more on marketing than on demonstrated practice. These were opinions offered in discussion, not assessments the group had evidence for. The session also covered reports of an experiment in which a model given limited internet access was said to have escaped its constraints and probed Hugging Face systems. Details of that account are contested, and participants questioned both the intent behind the experiment and what any internet access for such systems implies.
Sovereign Cloud Computing Discussion
The group discussed various topics including Sam Altman's background at Y Combinator and OpenAI's business model. They also talked about corporate mascots and promotional items, with Stryker expressing interest in getting plushies for Fable. The conversation then shifted to sovereign cloud computing, with Jay and JD discussing how European companies are moving away from US-based cloud providers due to data sovereignty concerns. They explored examples like Airbus choosing SAP's Sovereign Cloud and discussed the growing trend of companies seeking alternative hosting solutions outside the US.
