The AI Arms Race: From Governance to Runtime Control in an Autonomous Threat Landscape

You just heard how organizations are moving from governing systems to governing within them, and how the ACE Framework and AARM work together to keep authority accountable as AI agents take on more autonomous action. Everything from the session lives here: the CISO Action Brief, a discount on the book, and more on both frameworks.

Thank you for joining us at Black Hat's CISO Summit!


“Security leaders have an opportunity to move from being seen primarily as risk reducers to becoming essential partners in operational reliability, trusted scale, and AI value creation.”

— Camille Stewart Gloster

Download the CISO Action Brief

A practical extension of the session, the CISO Action Brief deepens the core concepts and translates them into actionable guidance for governing delegated authority in adversarial environments.

The Insider You Built

Get Your Discounted Copy

How Organizations Stay in Control of Autonomous AI Agents

AI is moving from answering questions to taking action. This book shows leaders, teams, and individuals how to get real value from AI without giving up control.

By Camille Stewart Gloster, former Deputy National Cyber Director at the White House.

Available September 15, 2026 from Wiley.

Event Discount Link

"Mandatory reading for any leader leveraging AI in real-world environments."

— Rob Duhart Jr., Chief Security Officer, Oracle

Learn More About ACE and AARM

AARM is a technical standard for implementing runtime enforcement within the ACE Framework. ACE defines, governs, and adapts the authority an organization delegates while helping it coordinate control across organizational, operational, and technical layers. AARM operationalizes those decisions by intercepting, evaluating, and enforcing proposed actions at the moment an agent attempts to act. The two are complementary: ACE establishes and continuously adapts the operating model; AARM enforces its technical boundaries at runtime.

ACE

The Authority-Centered Enforcement™ Framework is a practical governance architecture for the age of delegated authority.

ACE helps organizations embed control into the way autonomous systems and organizations operate. It gives leaders a structured way to define what authority has been granted, establish the conditions under which that authority may be exercised, preserve visibility into decisions and actions, and intervene when systems move beyond intended boundaries.

ACE is designed for the shift from governance of systems to governance within systems.

AARM

The system category for agentic runtime security.

AARM is the system category specification for agentic runtime security — it defines the capabilities an agent security system must provide to govern what an AI agent is allowed to do at runtime.

93

companies building on AARM

Learn more @ AARM.dev

7

completed a formal conformance review

Additional Resources

Get the Latest Insights

Subscribe to The Signal, the CAS Strategies newsletter, and follow Command Line with Camille substack for practical insights from the front lines of AI implementation. The work draws across organizations of different sizes, sectors, structures, and levels of maturity to surface what is working, where governance is breaking down, and what security leaders should be preparing for next.

The Signal is our bi-monthly briefing on the trends shaping AI, cybersecurity, and digital governance.

Insights from our founder on the forces shaping AI, cybersecurity, and digital resilience.

Your Presenters

Camille Stewart Gloster

Technology executive, Founder and CEO of CAS Strategies, and author of The Insider You Built: How Organizations Stay in Control of Autonomous AI Agents. She is one of the few leaders who has built and operated across national security, enterprise execution, and the environments where emerging technologies move from ambition to reality. Across roles spanning government and industry, including Google, Deloitte, DHS, and CrowdStrike, she has helped organizations govern, secure, and operationalize emerging technologies at scale.

Website | Linkedin

Herman Errico

Technology and security leader at Vanta and creator of Autonomous Action Runtime Management (AARM), an open specification for securing AI-driven actions at runtime. His work focuses on the emerging security boundary created when AI systems move from generating outputs to executing consequential actions. He develops practical approaches to action authorization, policy enforcement, provenance, and runtime controls that help organizations govern autonomous systems before decisions become irreversible.

Linkedin


“The security boundary is no longer just who can access a system. It is whether an autonomous action should be allowed to execute in that moment.”

– Herman Errico