Elisity Joins Open Secure AI Alliance
In a pivotal move to enhance AI safety and cybersecurity, Elisity, renowned for its identity-based microsegmentation solutions, has officially joined the Open Secure AI Alliance. This coalition, spearheaded by the Linux Foundation, aims to foster collaboration among organizations to develop and share open-source tools, techniques, and technologies designed to safeguard software and AI agents.
Understanding the Alliance's Mission
The Open Secure AI Alliance brings together a diverse group of stakeholders dedicated to addressing the vulnerabilities present in AI systems. With technology evolving rapidly, securing AI agents, which can operate across various applications, infrastructures, and service providers, becomes increasingly crucial. To facilitate this, the members, including Elisity, are focused on integrating identity systems, threat detection, application permissions, and segmentation controls. Together, they aspire to cultivate an environment conducive to consistent AI governance and security.
James Winebrenner, the CEO of Elisity, emphasized the necessity for a standardized approach, stating, "Enterprises need a consistent way to secure AI agents as they move across technologies from different providers." He explained that Elisity’s strength lies in bringing together contextual data from customers' security tools, which can be translated into enforceable segmentation policies, thereby expanding the boundaries of collaboration within the Alliance.
Collaborative Ecosystem Approach
Elisity's commitment to collaboration is deeply embedded in its operations. The firm's existing partnerships with leading platforms such as CrowdStrike Falcon, Microsoft Active Directory, Armis, and ServiceNow CMDB exemplify its collaborative philosophy. Through their IdentityGraph technology, Elisity correlates identity, asset, and risk information from these valuable sources, informing segmentation policies that are enforced through existing network infrastructure. This holistic approach aims to empower enterprises to make informed decisions regarding the permissions and access granted to AI agents operating within their environments.
Focus Areas for the Alliance
As part of this new engagement, Elisity is set to contribute to three primary security priorities:
1.
Least Privilege for Sanctioned Agents: Establishing uniform methods to define an agent's identity, ownership, and authorized functions is paramount. Such frameworks enable security controls to apply appropriate limitations across various platforms. Through these standards, sanctioned agents are treated like internal actors, and their access must be continually justified based on their roles and risk levels.
2.
Containment of Agentic Threats and Attacks: The necessity for shared strategies to communicate risks and execute containment across security systems cannot be ignored. Enforceable boundaries and interoperability among controls are vital to restricting threats that can act swiftly within a network.
3.
Identification of Unsanctioned AI: The Alliance aims to refine the processes involved in detecting unauthorized AI use, including employee-installed software and newly connected AI services. By developing common methodologies, organizations can better discern between legitimate activities and potential risks, leading to informed policy decisions.
Jason Elrod, CISO at MultiCare Health System and an advisor to Elisity, noted the critical importance of understanding who owns an AI agent and what access it requires. He advocates for shared standards that provide consistency in managing AI technology across clinical applications and security tools.
The Importance of Open Standards
Mike Searight, a former CIO and now an advisor to Elisity, pointed out that public-sector teams must collaborate with their technology providers to manage access and enforce limits. This collaboration is key to maximizing existing infrastructures and resources when integrating new AI tools.
Elisity views its alliance participation as an extension of its commitment to optimizing enterprises' security investments. The company's vision for AI-agent security hinges on ecosystem collaboration, with shared standards at the core of connecting identity, permissions, and enforceable measures as AI technology continues to gain traction.
For more information on the Open Secure AI Alliance and Elisity’s initiatives, please visit their official website.
About Elisity
Elisity is dedicated to helping healthcare systems, manufacturers, and critical infrastructure operators prevent lateral movement in their networks through identity-based microsegmentation. By leveraging identity and risk context for users, devices, and workloads, the company's platform facilitates the discovery of assets, simulation of policies, and enforcement of least-privilege access without necessitating new hardware or network redesign. Major clients include GSK, Main Line Health, and MultiCare Health System. For additional information, visit
www.elisity.com.