The Operating Discipline for AI Library™

Cloud and Infrastructure Security in the Age of AI™

Securing the Cloud and Infrastructure That Machines Now Operate

Available now

Book 09 of 9 in The Operating Discipline for AI Library™, Book 5 of 5 in AI Risk Governance & Security™. Cloud security was built on a single premise: that every meaningful action could be traced to an accountable human. AI has broken that premise in three places at once: non-human identities now outnumber human ones by an order of magnitude, infrastructure changes happen at machine pace while approval and audit operate at human pace, and the audit chain no longer cleanly answers who did this, on whose behalf, with what authorization. This book introduces The Sovereignty Problem and provides the working frameworks cloud security leaders need to catch up.

Buy on Amazon → Hardcover, paperback, and Kindle editions.
Editions

Hardcover, 258 pages, ISBN 979-8-9981369-5-5. Paperback, ISBN 979-8-9981369-0-0. Kindle edition, ISBN 979-8-9981369-2-4. Published September 23, 2026 by SRJ Consulting & Services Publishing. Book 09 of 9 completes The Operating Discipline for AI Library™ and closes AI Risk Governance & Security™. Every figure from the manuscript and all fourteen instruments of the Engineer’s Toolkit are free to download below.

Cloud and Infrastructure Security in the Age of AI™ book cover
For Librarians

What every Librarian needs to know about this book!

Volume IX of The Operating Discipline for AI Library™ · 258 pages · Hardcover ISBN 979-8-9981369-5-5. The library sell sheet fits on one page and carries the full bibliographic record, ISBNs and list prices for every format, a summary of what is inside, and the collections the book suits.

Download the Library Sell Sheet (PDF) ↓
Executive Briefing
Cloud and Infrastructure Security in the Age of AI™
PDF · 26 Slides
Read the Briefing

The executive briefing, in one page at a time.

A condensed visual companion to the book. The Sovereignty Problem and the three questions every action must answer, the controls that report green and fail a test, why reversibility is the most underweighted variable in cloud risk, the Cloud Sovereignty Score, and the first three moves: count, bind, lock. Twenty-six slides, built for the engineers who own the estate and the leadership team that answers for it.

The majority of actors in your cloud accounts are no longer human.

Three breaks happened simultaneously and they are inseparable. The identity ratio inverted: non-human identities now outnumber human ones by an order of magnitude, and the trend continues. Infrastructure pace outran governance pace: changes that used to take a person an hour now happen in seconds across thousands of resources, while the approval and audit processes designed to govern them still operate at human pace. And the accountability chain that cloud audit logs exist to preserve no longer has a clean answer to its central question when the actor is an AI agent operating on behalf of a workflow that itself was triggered by another agent.

This book names that combined condition The Sovereignty Problem and treats it as the defining cloud security shift of this technology cycle. Teams that solve it use AI to finally compress the identity, posture, and threat detection work that has been crushing them for a decade, and they rebuild their governance model around the new reality. Teams that do not operate cloud environments where the audit log no longer answers the question it was designed to answer, and they will not realize it until a regulator, customer, or incident makes them.

Can your estate say who acted? Start with a conversation about the three questions.

Your controls report green. Your examiner still gets a letter that says believe.

Most estates can revoke a role, restore a bucket, and deny an action. That is control, and most teams have it. What they cannot do is say which identity acted, what it was permitted to do on whose behalf, or whether anything would have caught the action in time. That is sovereignty, and a team can have complete control and still fail all three questions.

The most consistent finding in the book was not a missing control. It was a control that existed, reported green, and did not do what everyone assumed: images signed but never enforced where it mattered, tokens shown revoked at the console while an exchanged token kept reading, plan checks that quietly skipped excluded workspaces. Each would pass a checklist. Each failed a test, which is why a green posture score and a failed examination can describe the same morning.

Green posture, unanswerable audit? That gap is the engagement.

What this book gives you

At its center are five working frameworks cloud security leaders can apply directly: The Cloud Attack Surface Map™ (the surface extended to include AI workloads, agent identities, model artifacts, and machine-paced change vectors); The Non-Human Identity Equation™ (the model for governing the identity explosion through classification, lifecycle, scoping, and accountability); The Blast Radius Calculus™ (the framework for evaluating risk in machine-paced environments, where small actions can produce catastrophic outcomes routinely); The AI Cloud Security Lifecycle™ (the integrated operating model that merges cloud security operations with AI-specific controls); and The Cloud Sovereignty Score™ (the maturity model and assessment tool, a defensible way to measure whether a cloud security program has caught up to the AI era).

The frameworks integrate with existing CSPM, CNAPP, CIEM, and SIEM investments rather than replacing them, and align with NIST SP 800-207 Zero Trust Architecture, the CSA Cloud Controls Matrix, and emerging cloud audit standards.

Count. Bind. Lock. The first three moves start with one call.

Who it's for

Cloud security architects, CSPM/CNAPP/CIEM operators, platform engineering leaders, identity and IAM teams, SRE and DevOps leaders, CISOs with significant cloud footprint, and compliance and audit leaders preparing for the next wave of cloud audit requirements. Precise enough that a principal cloud engineer respects it, accessible enough that a VP of Platform Engineering reads it on the plane.

The Engineer’s Toolkit

Fourteen working instruments ship with the book, one for every chapter’s artifact, from the Sovereign Gap Worksheet and the Cloud Attack Surface Map through the Shared Responsibility Line, the Isolation Tier Table, the NHI Register Schema, the NHI Lifecycle Standard, the Evaluation Latency Scorecard, the Blast Radius Calculator, the Delegation Chain Evidence Page, the Tooling Coverage Matrix, and the Cloud Sovereignty Score Assessment. They build on each other in that order. Every figure behind them, and every framework diagram from all fourteen chapters, is in the Chapter Graphics Library below, free to download and use within your organization today.

How the book and the Cloud and Infrastructure Security in the Age of AI engagement work together

The book is the operating manual, written for the cloud, platform, and identity engineers who will run the program themselves: the surface map, the nonhuman identity register and lifecycle, the change controls, the blast radius calculator, and the audit chain, installed against their own estate. The Cloud and Infrastructure Security in the Age of AI™ engagement is the execution of that model, designed for organizations that want the sovereign gap measured, the nonhuman identity register built, the delegation chain bound at execution, and the Cloud Sovereignty Score taken inside a defined timeline, not learned, drafted, and refined over two quarters of internal effort.

Teams that want the discipline in book form work from the book. Teams that want the register built against their own cloud accounts, enforcement moved from the ticket to the plan, and the evidence captured for their own examiners, work directly with the firm.

Free downloads for this book

The worksheets and templates that ship with this book are free. Enter your email once, click the confirmation link we send you, and every book's downloads unlock across the site, forever.

The Consulting Toolkit

Every operating instrument, editable and ready to run.

The fourteen operating instruments from the book, free and editable, one for every item in the Engineer’s Toolkit. Each chapter produces one, they build on each other in order, and the Cloud Sovereignty Score, dated and repeated, becomes the next year’s baseline. The spreadsheets work in Microsoft Excel, Google Sheets, Apple Numbers, and LibreOffice Calc; the fill-in forms open in any word processor.

Recommended Starting Point
The Sovereign Gap Worksheet

One page, four measurements, repeated against the same scope: the sovereign gap in seconds of machine action per review hour, evaluation latency against the reversibility window, and one timed reconstruction drill. It is the first dated evidence that attribution is its own property.

Download the Sovereign Gap Worksheet →
Chapter Graphics Library

Visual frameworks, ready for your presentations.

Every diagram, framework, and chart from the book is available here as an individual file. Use them in your slide decks, internal memos, board presentations, or training sessions. Free to use within your organization. Browse by chapter, click any image to download.

The Series

Explore the full book series.

The Operating Discipline for AI Library™ is the nine-book series across two pillars — AI Business Services™ (four books) and AI Risk Governance & Security™ (five books) — each mapped to one of the nine SRJ service lines. Browse the series, or speak with us directly about applying the framework in your organization.

Publication details

Series
The Operating Discipline for AI Library™, Volume 9
Published
September 23, 2026
Length
258 pages
Publisher
SRJ Consulting & Services Publishing
Editions, ISBNs, and list prices
EditionISBN-13List price
Hardcover979-8-9981369-5-5$109.99
Paperback979-8-9981369-0-0$46.99
Kindle979-8-9981369-2-4$24.99

Buy on Amazon List prices shown. Retailer pricing varies.