The AI risks security can actually control.
KTP does not expand the CISO's job infinitely. It clarifies the subset of AI risk security can govern, where to enforce it, and how to reduce blast radius at machine speed.
§01eleven reasons in ciso terms
Eleven translations of the framework into the language a security leader uses on Monday morning. Each is a reason this work earns space on the roadmap, and each maps to a control surface that already exists in the stack.
A risk register you can act on
Of the MIT risk universe, about a fifth — 337 risks — are directly controllable via runtime enforcement or strongly reducible. The remainder require governance, policy, or business controls. The register stops being a list of categories and starts being a list of controls with owners.
Where security actually has leverage
Security-controllable risks separate cleanly from non-security-primary risks. Data access, exfiltration, tool misuse, credential abuse, autonomous workflows, cross-boundary movement, financial actions, and multi-agent propagation belong to security. Labor displacement, training bias, market concentration, and broad cultural effects do not.
A new control layer
Zero Trust controls access. KTP controls consequence. The new layer evaluates the action itself: who is acting, what verb is being attempted, on what object, in what context, with what blast radius, and with what right of veto.
Enforcement points you can name
Agent runtime, tool gateways, API gateways, identity and delegation, data layers, transaction systems, network egress, human approval workflows. You now know where to put controls, not just that you need them.
TTGD compression
Without runtime enforcement: AI incidents at machine speed, late detection, manual containment, large blast radius. With it: pre-authorized actions, inline enforcement, automatic escalation, immediate containment. Time to good decision compresses from hours to seconds.
Audit and accountability
Trajectory-level logs, purpose-bound actions, delegation chains, runtime policy decisions. Incidents are explainable with precision rather than reconstructed with guesswork. The trajectory ledger becomes the new audit trail.
A defensible AI security strategy
Walk into a board meeting and say: we evaluated the MIT AI risk universe, identified which risks are controllable at runtime, mapped those to enforcement mechanisms, built a control architecture, and can show what we can prevent, constrain, detect, and what we cannot. That posture is rare right now.
Budget justification
Instead of asking for AI security tools in the abstract, request enforcement at agent runtime, tool gateways, and data boundaries to control the subset of AI risks that operate through autonomous action and system movement. The ask ties directly to the MIT taxonomy, measurable risk, and real incident pathways.
The next architecture shift
Perimeter security asked: is it inside? Identity asked: who is it? Zero Trust asked: should it access this? KTP asks: should it do this, here, now, in this sequence, with this consequence? The control plane moves from access to motion.
A board-ready narrative
AI risk becomes dangerous when systems can act at machine speed without constraints. This work identifies which risks depend on that behavior and defines how to control those actions in real time. One paragraph. Survives translation through legal, audit, the board, and the press.
Authorized is not appropriate
An agent can hold every valid permission, in a calm environment, and still be one keystroke from the wrong act for the moment: the cheerful all-hands newsletter an hour after layoffs, the deploy during an unrelated SEV-1, the record pulled during active litigation. None of these are capacity failures, so identity and access controls pass them clean. This is the second gate, appropriateness, and it is net-new governance surface that no IAM or ZTNA tool owns today.
§02the not-my-risk boundary
AI risk is being handed wholesale to security teams. The framework draws the line. The action layer is yours. The structural layer is shared with policy, governance, HR, legal, and the business.
The action layer
- Agent access
- Tool execution
- Data movement
- Credential use
- API invocation
- Autonomous transactions
- Cyber misuse
- Runtime telemetry
- Containment
- Audit trails
The structural layer
- Labor displacement
- Social trust erosion
- Market concentration
- Broad bias in society
- Institutional legitimacy
- Cultural effects
KTP does not expand the CISO's job infinitely. It clarifies the subset of AI risk security can actually govern. Where the bounded claim is documented: methods.
§03board-ready talking points
Four lines that travel. Use them in the deck, the readout, the memo, the hallway. Each one is short enough to repeat and sharp enough to land.
We do not need to control every thought an AI system has. We need to control every consequential action it can take.
KTP is the missing middle between AI policy and AI incidents.
Zero Trust controls access. KTP controls consequence.
Machine-speed risk requires machine-speed refusal.
§04budget justification frame
Every security budget request fails the same way: the ask is vague, the scope is unbounded, and the success criteria are unwritten. This reframes both sides of the same line item.
The ask that fails
"We need AI security tools."
- Generic framing. Hard to defend in a budget review.
- No defined scope. The line item grows without limit.
- No success criteria. Procurement leads, strategy follows.
The ask that lands
"We need enforcement at agent runtime, tool gateways, and data boundaries to control the subset of AI risks that operate through autonomous action and system movement."
- Tied directly to the MIT AI risk taxonomy.
- Tied to measurable risk and real incident pathways.
- Tied to named control surfaces in the existing stack.
The same insight, four registers
Pick the register that fits the room. The CISO-grade line is the one that lands in the security review.
AI risk becomes operationally governable at the boundary between cognition and consequence.
We do not need to govern every thought an AI system has. We need to govern every consequential action it can take.
KTP is an action authorization plane for autonomous systems.
KTP tells us which AI risks security can actually control, where to enforce those controls, and how to reduce blast radius at machine speed.