What changed
Trustworthy Autonomy™ is the new posture for AI on the vCISO Lite platform. Agents can now run programs end-to-end: every action they propose is cryptographically signed, bound to a specific control, backed by a reasoning trace, and re-verified against fresh evidence. Nothing runs on its own until you say it can.
Why it matters
Compliance AI has been a decade of promises and demo-call magic. What has not shipped, until now, is the audit chain underneath: a proposed action tied to the control it serves, the evidence it rests on, the person who approved it, and a signature that survives a Type II testing procedure in month six.
Every claim on the Trustworthy Autonomy landing page was designed against two documents: OWASP’s Top 10 for Agentic AI Security and the Cloud Security Alliance’s Agentic NIST AI RMF Profile v1. Both ask for the same underlying capabilities: kill switches, accountability registers, provable delegation chains. We built to those; the trust ladder on the landing page walks through how.
The full working paper, “A Framework and Benchmark Methodology for Certifying Autonomous GRC Agents” (Smith, 2026), and the executive brief are on the briefs & specs page. For the formal launch announcement, see the press release. For the underlying methodology and how our own market-research sprint shaped it, see the Trustworthy Autonomy blog cluster, including “How often is your compliance AI actually right?”
Availability
Shipping today across the platform. Every tier gets the posture; the agent catalog you can turn on tracks your existing entitlements.
The programs available on day one are third-party risk (score vendors, chase questionnaires, escalate exposure, keep the register audit-clean), audit prep and defense for SOC 2, ISO 27001 and PCI DSS, real-time KRI monitoring with drafted responses on threshold breach, and end-to-end M&A cyber diligence covering attack surface, third-party concentration, and data and regulatory exposure. Hand over as much or as little of the work as you want.
Known limitations
This is the first iteration of the Trustworthy Autonomy posture. The agent catalog covers the programs the platform already runs; new program types land per the roadmap rather than through agent extension.
Signed-action binding requires the control to be in scope on an active assessment. Frameworks you have not activated cannot anchor an agent's proposed action.
Autonomy level is per-control and defaults to propose-and-approve on first activation. Raising a control to run-without-approval is a deliberate decision recorded in the audit chain.