Cloud Security Alliance names Troy Leach to AI body
Mon, 14th Sep 2026 (Today)
Cloud Security Alliance has appointed Troy Leach as Executive Director of the CSAI Foundation. Leach is currently Chief Strategy Officer at the organisation.
The move puts a long-serving cybersecurity executive at the head of the foundation Cloud Security Alliance created to focus on AI security and safety. Leach brings more than 25 years of experience in cybersecurity, technology standards and digital trust.
His appointment comes as companies and public bodies deploy AI systems across a wider range of business and social functions, including systems with increasing autonomy. The CSAI Foundation is intended to provide a forum for industry, government, academia and the wider cybersecurity community to address risks, practices and trust frameworks tied to AI.
As Chief Strategy Officer at Cloud Security Alliance, Leach has overseen corporate strategy and supported the group's education, research, programmes and membership work. His background spans standards-setting, engagement with regulators in multiple jurisdictions and research into emerging risks.
Leadership shift
The appointment expands Leach's role from strategy into a more public-interest and convening position at a time of growing scrutiny of AI governance. Cloud Security Alliance launched the foundation as a non-profit body dedicated to AI security and safety.
According to the organisation, the foundation's work includes risk intelligence, operational best practice, certification, executive collaboration, assurance work and research related to the governance of autonomous AI systems. It has framed part of that work around what it calls the "agentic control plane", reflecting an emphasis on systems that can act with less human intervention.
Jim Reavis, Chief Executive Officer and Co-Founder of Cloud Security Alliance, announced the leadership change with a strong endorsement of Leach's track record. "We're thrilled to have Troy step into this role. He's spent his career helping shape cybersecurity standards and practices to make our digital world safer, and this promotion is a natural recognition of that leadership," Reavis said.
He added: "His deep understanding of how security standards evolve alongside technology will be especially valuable as we enter a new era of autonomous systems. We're fortunate to have him leading this effort."
Broad background
Leach's career has included work across industry groups, non-profit organisations and academic settings. He has helped establish and lead standards organisations, advised universities on cybersecurity curricula and worked with both commercial and charitable bodies.
That breadth matters for a foundation seeking to bring together stakeholders with different incentives and responsibilities. AI security policy increasingly spans technical controls, organisational governance, public accountability and workforce development, often requiring coordination across sectors rather than action by individual companies alone.
Leach's advisory work has covered both for-profit and non-profit organisations. Outside the sector, he also serves on the national board of Grateful Giving, a charity-focused micro-donation initiative.
In comments issued alongside the appointment, Leach pointed to collaboration as the central challenge for AI safeguards. "Effective safeguards succeed when stakeholders of the community work together to define outcomes that are technically sound, operationally practical, and worthy of public trust," Leach said.
He added that the foundation could turn collaboration into direct support for research and implementation. "The CSAI Foundation can turn that collaboration and philanthropic giving into action by supporting timely research and other practical cybersecurity needs. I am honored to lead this work and help build the shared knowledge and capabilities for a future increasingly shaped by autonomous systems that are secure, responsible, and broadly beneficial," he said.
AI focus
The leadership change underscores how established cybersecurity groups are adapting their structures to address AI-specific risks rather than treating them solely as an extension of cloud or software security. For industry bodies, that means expanding work on standards and education into questions of assurance, governance and trust for autonomous systems.
Cloud Security Alliance has built its profile around cloud security, Zero Trust and related education and research. By putting its Chief Strategy Officer in charge of the CSAI Foundation, the organisation is signalling that AI security and safety now sit closer to the centre of its agenda.
The foundation's stated mission is to advance secure and trustworthy AI through collaboration, education and public-interest initiatives.