Share with your CISO
Workday is joining the Open Secure AI Alliance, a Linux Foundation-backed coalition spanning cloud, cybersecurity, and enterprise software vendors, and using the move to articulate its layered security approach for agentic AI. The company’s defense-in-depth framework covers Agent Passport identity verification, post-quantum encryption upgrades, an AI-specific Secure Software Development Lifecycle, and academic research partnerships in Dublin spanning adversarial testing and LLM explainability. The through-line is that neither open nor closed model architectures are inherently safer, and that shared defensive tooling is the fastest path to closing industry-wide gaps.
What this means for your business
Any enterprise running HR or finance workflows through Workday sits inside a system that just made a public commitment to open, auditable security standards. That matters because the alternative, proprietary security claims you can’t independently verify, has historically been the norm for enterprise SaaS. CISOs evaluating agentic AI deployments now have a named framework to audit against: identity controls, permission boundaries, data protections, and continuous monitoring. Whether Workday delivers on that framework is a separate question, but the specificity creates accountability that vague “trust and safety” marketing doesn’t.
The most underappreciated claim here is the encryption posture. Workday explicitly mentions upgrading encryption to defend against advanced computing threats, a reference to post-quantum cryptography, the practice of replacing current encryption algorithms with ones designed to resist attacks from quantum computers, which can break today’s standards. Most enterprise vendors are not moving on this yet. If Workday’s timeline is real and a CISO’s current HR or finance vendor has no post-quantum roadmap, that gap belongs on the next renewal conversation, not the one after.
The piece, written by Workday’s own security team and naturally framed to flatter Workday’s existing investments, still lands a structurally honest point: open-source defensive tooling is only as good as the shared research behind it. Vendors publishing synthetic data generators and joining standards bodies don’t automatically make their customers safer, but they do shift the accountability surface. If you’re a CISO who has accepted “we take security seriously” as sufficient vendor assurance, this article is a signal that the bar is moving and your vendor contracts should move with it.
Concept deep-dive: Defense in Depth
Defense in depth is a security architecture principle borrowed from military strategy: no single barrier stops every attack, so you layer independent controls so that a failure in one doesn’t cascade into a breach. In enterprise AI, that means identity verification, access permissions, runtime monitoring, and governance don’t substitute for each other, they stack. The business relevance is that agentic AI, where software takes autonomous action across systems, multiplies the number of points where a single control failure becomes a critical incident.
Based on reporting from Trusted Enterprise AI Needs Defense in Depth, originally published 2026-08-06 03:00:00.

