OWASP — Open Worldwide Application Security Project

Sources: OWASP (homepage) · OWASP GenAI Security Project · OWASP Top 10 for LLM Applications

OWASP (Open Worldwide Application Security Project) is the leading open-source, community-driven security organization. In AI security, OWASP has become the de facto reference taxonomy producer — having published more substantive AI security content in Q1 2026 than any other framework organization.

AI Security Role

OWASP publishes awareness frameworks and risk taxonomies rather than certifiable compliance standards, with one qualification that has grown material. The OWASP AI Exchange states that it feeds normative standards directly through official liaison partnership, contributing 70 pages to prEN 18282 (cybersecurity for the EU AI Act), 70 pages to ISO/IEC 27090 (AI security), and further material to ISO/IEC 27091 (AI privacy).1 The output remains non-certifiable in OWASP’s own hands; the route to enforceability runs through the standards bodies OWASP contributes to. OWASP’s strength beyond that liaison route is community development (100+ experts for the ASI Top 10), vendor adoption, and the speed with which it can codify emerging threat patterns.

OWASP runs two flagship AI projects. The AI Exchange is the comprehensive threat-and-control framework covering all AI — agentic, analytical, discriminative, generative, and heuristic — and privacy alongside security; it was awarded flagship status in March 2025. The GenAI Security Project is the umbrella for generative-AI deliverables including the LLM Top 10, the ASI Top 10, and AIVSS. A third project, the OWASP AISVS (AI Security Verification Standard), supplies a three-level verification checklist aligned to ASVS and is the artifact the Exchange directs auditors to (/go/aiatowasp/).

Q1 2026 Activity

OWASP had the most productive AI security quarter of any framework organization:

  • OWASP Top 10 for Agentic Applications (ASI Top 10) — published December 9, 2025 at the Agentic AI Security Summit, London; adopted by Microsoft, Palo Alto Networks, Auth0, Gravitee in Q1 2026
  • AIVSS v0.8 (March 19, 2026) — first AI-specific vulnerability scoring system extending CVSS 4.0
  • Practical Guide for Secure MCP Server Development (February 16, 2026)
  • GenAI Security Project announcement at RSAC 2026 (March 19) — updated Landscape Guide, GenAI Data Security Risks report, Agentic AI Security Solutions Landscape
  • OWASP AIBOM Generator — CycloneDX-format AI bills of materials for Hugging Face-hosted models

GenAI Security Project now has 25,000+ members with new sponsors including F5, Fujitsu, and Apiiro.

Notable Sponsor M&A Activity (Q1 2026)

Five OWASP sponsor alumni were acquired by major security vendors:

  • Pangea → CrowdStrike
  • Lakera → Check Point
  • Prompt Security → SentinelOne
  • Calypso AI → F5
  • SPLX → Zscaler

AI Security Frameworks Published

FrameworkStatus
LLM Top 10 2025Active; unchanged Q1 2026; codes verified by the LLM Top 10 review
Agentic Applications Top 10Active; published Dec 2025
ML Security Top 10 v0.3Dormant
AIVSS v0.8Active; community review
State of Agentic AI Security and Governance v2Active; published Jun 2026
AIBOM GeneratorActive
MCP Security GuideActive (Feb 2026)
AI ExchangeActive; OWASP Flagship since March 2025; 170+ authors; feeds prEN 18282 and ISO/IEC 27090 per the Exchange’s own liaison claim, unverified1
OWASP AISVSActive; three verification levels aligned to ASVS

Cross-Org Strategic Briefings

Notes

Footnotes

  1. OWASP AI Exchange, “About the AI Exchange”, retrieved 2026-08-17. The Exchange states 70 pages contributed to prEN 18282 and 70 pages to ISO/IEC 27090 through official liaison partnership, plus contribution to ISO/IEC 27091. These are the source’s own claims and are not independently verified here. 2