On June 26, 2026, the Cloud Security Alliance shipped version 1.1 of its AI Controls Matrix (AICM), the framework enterprise security teams use to vet AI vendors before signing a contract. The update grew the matrix from 243 control objectives to 247 across 18 domains and added something that did not exist in version 1.0: a dedicated Model Security domain, mapped to the EU AI Act, the NIST AI Risk Management Framework, and ISO/IEC 42001, according to Virtualization Review. If your product touches an enterprise security review in the second half of 2026, this is the document that is about to land on your desk.
The questionnaire got longer and more specific
The companion document buyers use to actually run the assessment, the AI Consensus Assessments Initiative Questionnaire (AI-CAIQ), grew alongside the matrix: it now runs 320 questions, aligned directly to the AICM v1.1 controls, according to Vorp Labs. That is not a checkbox exercise bolted onto an existing infosec review. It is a structured interrogation of how a vendor's model is built, monitored, and controlled, built specifically for AI vendors rather than adapted from a generic SaaS questionnaire.
What buyers are now gating on
Zylos Research, tracking enterprise procurement checklists as of July 2, 2026, found that buyers evaluating AI agent vendors now routinely demand these as conditions of deployment approval, not as nice-to-haves:
- Kill switches
- Evidentiary audit trails
- Human-in-the-loop boundaries
- Model change control
- Outcome-based SLAs
- ISO/IEC 42001 or SOC 2 attestation
None of these were standard line items in a vendor security review two years ago. Now they gate the deal, meaning a vendor without them does not reach the pricing conversation, per Zylos Research.
Certification is becoming table stakes
ISO/IEC 42001, the AI management system standard, had more than 350 organizations certified worldwide as of mid-2026, and BrightDefense reports it is increasingly required as a procurement gate by financial services and healthcare buyers specifically (BrightDefense). Shared Assessments folded the same standard into its 2026 SIG (Standardized Information Gathering) questionnaire update, mapping AI governance into the standard third-party due-diligence workflow instead of treating it as a special case (Shared Assessments).
Regulation is setting the floor
Three regulatory deadlines are doing the enforcing behind this. Under the EU AI Act, high-risk AI systems used in financial services must meet transparency, traceability, and human-oversight requirements by August 2, 2026, and financial institutions are now expected to be ready to disclose their AI vendors' controls and safeguards to counterparties such as Fannie Mae on request, according to Plante Moran. Separately, as of July 1, 2026, 25 U.S. states have adopted the NAIC Model Bulletin on AI, which requires insurers to conduct due diligence on AI vendors' governance practices and to hold contractual rights to audit or terminate the relationship, with 8 more states in the adoption process (actuary.info). And NSPM-11, issued June 5, 2026, set a federal benchmark for AI security in national-security contexts, forbidding unauthorized modification of AI assets and requiring live monitoring and annual compliance reviews, a standard now referenced by name in commercial vendor risk frameworks (FifthRow).
Gartner's "Predicts 2026: Third-Party Cybersecurity Risk Management Evolves for the AI Era" forecasts that by 2028, 70% of organizations and vendors will use generative AI on both sides of the security questionnaire process, a shift Gartner says speeds up the paperwork without necessarily improving anyone's actual risk insight, according to Gartner, via RiskRecon.
The practical shift for founders selling into the enterprise: the vendor security review is no longer a generic infosec checklist with an AI section bolted on. It is becoming AI-specific, standardized across CSA, Shared Assessments, and state insurance regulators, and gated on capabilities like kill switches, audit trails, and human-in-the-loop controls that most AI startups have not built yet.
This week, pull your last three stalled or lost enterprise deals and check what the security questionnaire actually asked for. If it asked about model change control, a kill switch, or ISO/IEC 42001 and your team had no answer, that gap is your product roadmap for the next quarter, not a line item in the feature backlog.