All press releases

For Immediate Release

vCISO Lite Launches Trustworthy Autonomy™ — Autonomous Agents That Run Cyber Risk, Compliance, and Diligence Programs End-to-End, With Cryptographic Proof of Every Action

AI agents that run TPRM, audit prep, KRI monitoring, and M&A cyber diligence — with cryptographic proof of every action and a trust ladder that lets agents earn autonomy at their customers' pace.

ATLANTA — July 7, 2026 — vCISO Lite today launched Trustworthy Autonomy™, a new posture for autonomous AI on the vCISO Lite platform. Trustworthy Autonomy pairs AI agents that run cyber risk, compliance, and diligence programs end-to-end with cryptographic proof of every action the agent takes — and a trust ladder that lets the agent earn autonomy at the customer’s pace rather than being granted it upfront.

The launch responds to what Help Net Security has called “pilot purgatory”in agentic AI for security operations: a market state in which vendor promises of full autonomy fail to survive real production deployment, and customers keep humans in the loop out of necessity. vCISO Lite’s own five-week research sprint on the state of agentic AI in security — 24 sources, 120 claims, 3-vote adversarial verification — corroborated the finding across every lens surveyed.

“Every autonomous-AI pitch in security this year runs into the same three questions: what did the AI decide, signed by what, verified against what evidence,” said Yolonda Smith, founder of vCISO Lite. “Buyers don’t get answers, so they keep humans in the loop and the promise never lands. We built for the opposite — every action our agents propose is cryptographically signed, bound to a specific control, backed by a reasoning trace you can read line by line, and re-verified against fresh evidence. Trust accrues at the customer’s pace. It doesn’t get granted on a demo call.”

What’s in the release

Trustworthy Autonomy enters public beta today on the vCISO Lite platform, opening a design-partner cohort for customers who want to shape the production roadmap. In the beta release, design partners can hand end-to-end operational responsibility to the agent across the following programs:

  • Third-party risk management (TPRM)— vendor scoring, questionnaire completion, exposure escalation, and register maintenance.
  • Audit preparation and defense— SOC 2, ISO 27001, and PCI DSS evidence collection, control implementation, and finding remediation.
  • Real-time key risk indicator (KRI) monitoring— threshold-triggered notification, drafted response, and human approval gating.
  • End-to-end M&A cyber diligence engagements— using the Quantitative Cyber Diligence framework published in the founder’s 2026 book, Someone Else’s Debt.

Every action the agent proposes is cryptographically signed (Ed25519), bound to a specific control (SOC 2 CC6.1, PCI 8.3.1, ISO 27001 A.5.15, and so on), backed by a reasoning trace the customer can inspect, and re-verified against fresh evidence rather than a stale snapshot. Every framework mapped in the Secure Controls Framework (SCF)is supported by default — including DORA, NYDFS Part 500, HIPAA, GDPR, NIST 800-53 and 800-171, FedRAMP, CMMC, and every state-level and sector-specific equivalent that inherits from the same control primitives.

What mature autonomous AI in security looks like

The engineering was designed against four recent standards releases that, together, codify what production-grade autonomous AI in a privileged environment actually requires:

  • OWASP’s Top 10 Risks and Mitigations for Agentic AI Security— published December 9, 2025 by 100+ researchers and reviewed by a board including NIST, the European Commission, and the Alan Turing Institute. Names goal hijacking, tool misuse, and identity/privilege abuse as the top production risks of autonomous AI.
  • The Cloud Security Alliance’s Agentic NIST AI RMF Profile v1— published alongside OWASP’s Top 10. Defines a graduated autonomy taxonomy (Tier 1 supervised through Tier 4 full) and calls for infrastructure-level kill switches, automated agent suspension, and per-agent accountability registers documenting the human delegation chain behind every autonomous action.
  • The Databricks AI Security Framework (DASF) v3.0— released March 2026 with a dedicated Agentic AI layer added as the framework’s 13th canonical system component. Adds 35 new technical security risks addressing agent memory, planning, tool use, and threats introduced by the Model Context Protocol (MCP), plus 6 additional mitigation controls specific to autonomy.
  • ISO/IEC 42001— the international AI management standard, published December 2023 as the harmonized-backbone counterpart to ISO 27001 for AI. Requires an AI management system with lifecycle records, a distinct AI system impact assessment in addition to the AI risk assessment, and the plumbing to inform affected parties when an AI decision touches them. First mid-market audits land in 2027; vCISO Lite’s analysis of what those audits will require is in the company blog’s AI Governance series, starting with “The 2027 ISO 42001 AI audits most mid-market companies will fail.”

Trustworthy Autonomy implements the OWASP mitigations, the CSA profile’s recommended controls, the DASF Agentic AI additions, and ISO 42001’s program-level requirements as first-class product features — not because the standards demand them, but because they describe the mechanisms that make autonomous AI in a privileged environment actually safe. The full methodology is published in the accompanying working paper, “A Framework and Benchmark Methodology for Certifying Autonomous GRC Agents” (Smith, 2026), available at vcisolite.com/trustworthy-autonomy.

Availability

Trustworthy Autonomy is in public beta today on the vCISO Lite Enterprise tier, with a design-partner cohort open for customers who want to collaborate on the roadmap for scoped autonomy (Rung 2, anticipated H1 2027) and goal-oriented autonomy (Rung 3, anticipated H2 2027 or later). General availability will follow as the eval harness matures and each rung is validated against real design-partner deployments. The executive brief and working paper are available at vcisolite.com/trustworthy-autonomy, with the full briefs and academic papers at vcisolite.com/briefs-and-specs.


About vCISO Lite

vCISO Lite is a compliance and cyber risk platform for growing companies that don’t have a full-time CISO. The platform helps customers close compliance gaps (SOC 2, ISO 27001, PCI DSS, HIPAA, and more), quantify cyber risk in the language their board and deal teams already speak, and now — with Trustworthy Autonomy — hand operational responsibility to AI agents that prove every move they make. vCISO Lite is headquartered in Atlanta, Georgia. Learn more at vcisolite.com, read related product releases in the changelog, or explore the Trustworthy Autonomy editorial series.

Media Contact

Press & Analyst Inquiries
Yolonda Smith, Founder
press@vcisolite.com

###

Related reading

How Often Is Your Compliance AI Actually Right? — the accuracy-standard framing Trustworthy Autonomy is anchored on.

The Trust Ladder: Compliance AI Autonomy — the four-tier ladder the Trustworthy Autonomy launch positions vCISO Lite on.

Autonomy You Can Audit: Signed Action Logs — the substrate that makes autonomous compliance auditable — the core claim of the launch.

Suggest-Only Is Where the Industry Stops — the vendor-landscape framing that shows why moving past suggest-only requires the substrate Trustworthy Autonomy ships.