Opens in a new tab
vmblog logo 2024 wht (updated)

AI Proving Ground Consortium: Why Enterprises Must Test AI Security Before Attackers Do, with Lee Rossey of SimSpace

Share: 

David Marshall | Published: July 23, 2026
interview simspace lee rossey

AI is moving into security operations faster than most organizations can prove it belongs there. Enterprises are racing to deploy autonomous AI agents into their SOCs, but autonomy without validation is a liability, not an advantage. The more independently these systems operate, the more rigorously they need to be tested — and with threats like Mythos and Daybreak already on the horizon, security teams can no longer afford to wait until an attack reveals whether their AI defenses actually hold up. That urgency is exactly what led a coalition of cybersecurity leaders to form the AI Proving Ground Consortium (AIPGC), a group dedicated to helping enterprises train, validate, and prove their AI systems in a controlled environment before those systems ever touch a live security operation.

VMblog sat down with Lee Rossey, CTO and Co-Founder at SimSpace, to unpack why this consortium exists, why no single vendor can solve AI security alone, and what a recent SimSpace survey reveals about the widening gap between confidence in AI defenses and the actual testing backing that confidence up. Rossey also shares insight into AIPGC’s ongoing event series, what enterprises should be asking as they move from proactive defense to preemptive resilience, and why the next era of AI in cybersecurity will be defined not by adoption speed, but by an organization’s ability to continuously prove its AI is ready for the real world.

++

VMblog: What is the AI Proving Ground Consortium and Why Propose this Solution to the Current Industry Problem? 

Lee Rossey: Enterprises are deploying AI into security operations faster than systems can prove trustworthy and AI agents are becoming increasingly autonomous, and the more autonomy, the greater degree of testing required to prove they’re good. There is also major urgency from companies to prepare for Mythos- and Daybreak-fueled attacks. These AI models and agents will target your environment, so you need a safe place to test whether your controls, detection, containment, and teams can withstand that threat. We’ve built this coalition of cybersecurity industry leaders to help enterprises train, test, validate and prove AI systems – BEFORE they are exposed in real-life security operations. True protection comes from realistic, hyper-synthetic data for enterprises deploying and improving models. The priority is continuously validating these models to protect against evolving threats. The consortium comes at the right time for the industry – helping leaders answer the practical questions to protect environments in the world of AI: What should we test? Where can AI fail? Ultimately, we’ll make the shift from proactive defense to preemptive resilience for AI protection.

​​​VMblog: Who Are the Key Members and W​​hat Is Their Purpose Benefit?

Rossey: AIPGC brings together the right mix of industry leaders to offer a clear picture of the full spectrum of AI in cybersecurity to solve the complexities of AI security. Companies benefit from the expertise of partner organizations such as SimSpace, Corelight, Dropzone AI, SCYTHE and Sondera. To better understand why realistic, hyper-synthetic data is critical for training and building realistic protection models, SimSpace provides a tier-one proving ground for cyber range realistic testing environments, while companies like Corelight deliver for customers network evidence, visibility and detection depth. With Dropzone AI, buyers gain expertise in proven autonomous SOC analysis, AI Agent experience, and SCYTHE brings adversary emulation and an offensive testing perspective. Rounding out the consortium is Sondera for tested AI security, while MITRE offers customers a fresh perspective direct from the independent analyst community. Buyers and companies benefit from a holistic group to gain a fresh perspective on how AI systems should be tested, validated, and trusted. ​     ​

VMblog: Why Can’t This Be Solved ​​with Just One Company?

Rossey: There’s no single company that OWNS the AI security lifecycle – it’s just not possible. We formed the consortium because we wanted to communicate this essential truth and we believe there is power in getting a message out to the world with more leaders coming together. While single vendors can evaluate their own tools, a true enterprise environment is a multi-vendor system that’s constantly changing. AI cybersecurity spans multiple, complex layers including data, telemetry, agents, workflows, validation and governance. Full trust in AI demands an ecosystem approach because AI agents don’t fail in isolation – they fail across data, models, controls, workflows, and human decision-making. Protection is based on understanding that realistic, hyper-synthetic data is key for training and building realistic protection models. The consortium helps companies avoid the trap of treating AI readiness as a checklist rather than an operational readiness problem.

VMblog: I Read a Recent Survey from SimSpace Regarding the Lack of Confidence in AI Testing. Tell Me About That.

Rossey: Yes, and it’s extremely relevant to what we’re talking about today. There’s a tremendous confidence gap between interest in AI and the readiness to deploy. While nearly 80% of CISOs report remarkably high confidence in their AI defenses, only 30% conduct live security exercises and only 29% conduct continuous simulation testing. The market is not rejecting AI but continuously struggling to prove when deployment is safe and ready. That’s one of the gaps the consortium is intended to fill. Confidence only comes from proof, and proof requires realistic testing. This survey reinforces that the market has now moved past curiosity and onto confidence. But the key is to make sure it’s ready for real-world security. 

VMblog: Is There A Current Event Series to Educate the Market?

Rossey: Absolutely, education is at the core of what the consortium does – educating the market on building ultimate trust in AI before deployment. The series began with focusing on the critical shift companies must make – moving from proactive defense to preemptive resilience. The July event then takes the next step by offering concrete guidance on how organizations can train, validate, and operationalize AI agents. As we’ve said, the market is continuously struggling to prove when AI deployment is safe and ready. As AI failures don’t happen in isolation, our intent is to bring together not only the expertise of founding members, but outside voices like MITRE to ensure the conversation is more practical and credible. The goal is to help CISOs, SOC and AI leaders and architecture teams understand how human analysis and AI can work together to measure confidence. Attendees will learn the most important points in the market today – production testing, agent validation, autonomy that is trusted and pre-emptive resilience. More information can be found here. Our next one is July 29, 2026 and we’ll have many more.

VMblog: What’s Next for AI in Cybersecurity ​​and How Can People Learn More?

Rossey: Looking ahead, the next phase isn’t deploying more AI, it’s proving AI continuously as models, attackers, and environments evolve. Think about it – specifically Mythos and Daybreak. Companies need to mitigate Mythos zero-days by testing whether its controls, detection, containment, and teams can withstand that threat. More organizations will deploy AI agents into security workflows, but the tough questions focus on trust and continuous validation under real-world deployment pressure. Security leaders must learn how to test AI continuously because threats, environments, and models will never stop changing. The future is not one AI agent replacing SOC, but multiple AI agents collaborating with humans across investigation, response, threat hunting and decision support. That’s what AIPGC is all about, and we encourage leaders from across key industries to attend the event series to start asking how they can prove AI readiness before production. Industry leaders can learn more by visiting AIPGC.ai, because organizations that win with AI cybersecurity will not be first adopters, but ones that understand how to trust it ​​responsibly. 

##