KTP/
github ↗
created 24 August 2026 · last modified 24 August 2026
for ciso & board

The AI risks security can actually control.

KTP does not expand the CISO's job infinitely. It clarifies the subset of AI risk security can govern, where to enforce it, and how to reduce blast radius at machine speed.

§01eleven reasons in ciso terms

Eleven translations of the framework into the language a security leader uses on Monday morning. Each is a reason this work earns space on the roadmap, and each maps to a control surface that already exists in the stack.

§01

A risk register you can act on

Of the MIT risk universe, about a fifth — 337 risks — are directly controllable via runtime enforcement or strongly reducible. The remainder require governance, policy, or business controls. The register stops being a list of categories and starts being a list of controls with owners.

§02

Where security actually has leverage

Security-controllable risks separate cleanly from non-security-primary risks. Data access, exfiltration, tool misuse, credential abuse, autonomous workflows, cross-boundary movement, financial actions, and multi-agent propagation belong to security. Labor displacement, training bias, market concentration, and broad cultural effects do not.

§03

A new control layer

Zero Trust controls access. KTP controls consequence. The new layer evaluates the action itself: who is acting, what verb is being attempted, on what object, in what context, with what blast radius, and with what right of veto.

§04

Enforcement points you can name

Agent runtime, tool gateways, API gateways, identity and delegation, data layers, transaction systems, network egress, human approval workflows. You now know where to put controls, not just that you need them.

§05

TTGD compression

Without runtime enforcement: AI incidents at machine speed, late detection, manual containment, large blast radius. With it: pre-authorized actions, inline enforcement, automatic escalation, immediate containment. Time to good decision compresses from hours to seconds.

§06

Audit and accountability

Trajectory-level logs, purpose-bound actions, delegation chains, runtime policy decisions. Incidents are explainable with precision rather than reconstructed with guesswork. The trajectory ledger becomes the new audit trail.

§07

A defensible AI security strategy

Walk into a board meeting and say: we evaluated the MIT AI risk universe, identified which risks are controllable at runtime, mapped those to enforcement mechanisms, built a control architecture, and can show what we can prevent, constrain, detect, and what we cannot. That posture is rare right now.

§08

Budget justification

Instead of asking for AI security tools in the abstract, request enforcement at agent runtime, tool gateways, and data boundaries to control the subset of AI risks that operate through autonomous action and system movement. The ask ties directly to the MIT taxonomy, measurable risk, and real incident pathways.

§09

The next architecture shift

Perimeter security asked: is it inside? Identity asked: who is it? Zero Trust asked: should it access this? KTP asks: should it do this, here, now, in this sequence, with this consequence? The control plane moves from access to motion.

§10

A board-ready narrative

AI risk becomes dangerous when systems can act at machine speed without constraints. This work identifies which risks depend on that behavior and defines how to control those actions in real time. One paragraph. Survives translation through legal, audit, the board, and the press.

§11

Authorized is not appropriate

An agent can hold every valid permission, in a calm environment, and still be one keystroke from the wrong act for the moment: the cheerful all-hands newsletter an hour after layoffs, the deploy during an unrelated SEV-1, the record pulled during active litigation. None of these are capacity failures, so identity and access controls pass them clean. This is the second gate, appropriateness, and it is net-new governance surface that no IAM or ZTNA tool owns today.

§02the not-my-risk boundary

AI risk is being handed wholesale to security teams. The framework draws the line. The action layer is yours. The structural layer is shared with policy, governance, HR, legal, and the business.

ciso owns or co-owns

The action layer

  • Agent access
  • Tool execution
  • Data movement
  • Credential use
  • API invocation
  • Autonomous transactions
  • Cyber misuse
  • Runtime telemetry
  • Containment
  • Audit trails
ciso influences but does not own

The structural layer

  • Labor displacement
  • Social trust erosion
  • Market concentration
  • Broad bias in society
  • Institutional legitimacy
  • Cultural effects

KTP does not expand the CISO's job infinitely. It clarifies the subset of AI risk security can actually govern. Where the bounded claim is documented: methods.

§03board-ready talking points

Four lines that travel. Use them in the deck, the readout, the memo, the hallway. Each one is short enough to repeat and sharp enough to land.

the boardroom line

We do not need to control every thought an AI system has. We need to control every consequential action it can take.

the gap

KTP is the missing middle between AI policy and AI incidents.

the maturity ladder

Zero Trust controls access. KTP controls consequence.

the speed argument

Machine-speed risk requires machine-speed refusal.

§04budget justification frame

Every security budget request fails the same way: the ask is vague, the scope is unbounded, and the success criteria are unwritten. This reframes both sides of the same line item.

vague

The ask that fails

"We need AI security tools."

  • Generic framing. Hard to defend in a budget review.
  • No defined scope. The line item grows without limit.
  • No success criteria. Procurement leads, strategy follows.
specific

The ask that lands

"We need enforcement at agent runtime, tool gateways, and data boundaries to control the subset of AI risks that operate through autonomous action and system movement."

  • Tied directly to the MIT AI risk taxonomy.
  • Tied to measurable risk and real incident pathways.
  • Tied to named control surfaces in the existing stack.
the four-grade thesis ladder

The same insight, four registers

Pick the register that fits the room. The CISO-grade line is the one that lands in the security review.

essay-grade

AI risk becomes operationally governable at the boundary between cognition and consequence.

board-grade

We do not need to govern every thought an AI system has. We need to govern every consequential action it can take.

architect-grade

KTP is an action authorization plane for autonomous systems.

ciso-grade

KTP tells us which AI risks security can actually control, where to enforce those controls, and how to reduce blast radius at machine speed.

next doors

Roadmap

Five phases from visibility to governance. The Tool Gateway as the headline.

Methods

Where the bounded claim is documented. Failure modes, the governability ladder, the v0.2 limits.

Skeptical

Concession first. Nine objections, answered. For the reader who does not want to be sold to.

How to cite
APA 7th ed.

Perkins, C. (2026, May 6). The AI risks security can actually control. Kinetic Trust Protocol. https://kinetic-trust-protocol.net/enterprise/ciso
Plain text

Chris Perkins, "The AI risks security can actually control," Kinetic Trust Protocol, https://kinetic-trust-protocol.net/enterprise/ciso (accessed May 6, 2026).