vertotechTrust Intelligence. Secure Every Outcome.
All research
AI Security·August 22, 2026·9 min read

AI Security Control Model: a production operating model

A gated framework for securing AWS, GCP, Azure, LLM applications, and agentic systems from estate discovery through audit-ready assurance.

VTVertotech Research

The AI Security Control Model is Vertotech's framework for making AI security operable. It packages lifecycle controls, cloud landing-zone invariants, runtime control planes, and policy gates into a model that can run in a delivery pipeline instead of living in a slide deck.

The model starts with a simple premise: a team cannot secure what it cannot name, own, classify, and observe. From there, it moves through four gates: Known estate, Secure by build, Protected in production, and Assured and auditable.

What the framework contains

  • Four lifecycle phases that move workloads from discovery to assurance.
  • Eight security domains covering asset posture, identity, development testing, runtime protection, data security, model supply chain, confidential infrastructure, and governance.
  • Fifty-nine lifecycle controls and sixty risk-driven technical capabilities.
  • Twelve control-plane layers, including runtime mediation, authorization, tool gateway, memory governance, sandboxing, observability, and lifecycle governance.
  • OPA-ready gate logic for evidence-driven assurance.

Why it is cloud-first

Modern AI systems inherit risk from the cloud they run on. The same operating model has to speak AWS IAM roles and CloudTrail, GCP service accounts and Cloud Asset Inventory, Azure managed identities and Defender for Cloud. The framework keeps those provider details concrete while preserving a cloud-neutral control structure.

Why agentic AI changes the operating model

Agentic systems do not only produce text. They call tools, read memory, write state, make plans, and cross trust boundaries. That shifts security into the runtime control plane: tool authorization, action approval, context validation, output enforcement, traces, and circuit breakers.

The anomaly the model makes visible

The threat catalog shows that runtime protection owns the largest share of technical AI risk controls. That is not a data problem; it is a production roadmap. Identity is the first perimeter, but runtime mediation is where many AI and agentic failures are actually stopped.

How teams use it

  • Run a diagnostic sprint against the current AI estate.
  • Map each workload's risk exposure to required controls.
  • Define gate evidence for CI, runtime, cloud posture, and audit exports.
  • Prioritize D4 runtime controls after the identity baseline is in place.
  • Train security and platform teams on the cloud-specific implementation path.

The public framework is maintained as code and designed to be extended. Use it as a research reference, a training spine, or the starting point for a production AI security operating model.

Working on something like this?

Tell us about the cloud estate, AI workload, or agentic system. We will map it to controls, policy evidence, and monitoring.

Book a briefing →