OWASP GenAI Security Project

Type: non-profit (project of the OWASP Foundation; community standards body — not a vendor, regulator or accredited certification body) Sector: open-source AI security guidance — Top 10 for LLM Applications, Top 10 for Agentic Applications, Agent Control Standard, AI Security Solutions Directory, Framework Crosswalk First seen: 2026-06-08 (as a referenced framework in S-2026-06-08-zenity-least-agency) Last updated: 2026-09-14

Created 2026-09-14 from S-2026-09-01-owasp-acs-llm-top10-2026 (daily AI-governance vendor-intelligence scan; OWASP press release, ACS resource page and GitHub spec fetched in full; CSA research note of 4 Sep fetched as independent corroboration). Page-creation trigger met: OWASP guidance was already the named reference point in three earlier Source pages (Giskard’s “OWASP Top 10 LLM compliance packs”; Obsidian Security’s “aligned to OWASP standards”; Zenity’s convergence with OWASP agentic guidance). Scope note: this page tracks the project’s outputs as they bear on AI-governance tooling and assurance evidence; it is not a general OWASP page.

Snapshot

The OWASP GenAI Security Project is the open-source community whose LLM Top 10 has become the de facto risk taxonomy that AI-security and guardrail vendors cite when they claim standards alignment — this vault has seen it invoked by Giskard [S-2026-07-23-giskard-hf-breach-guards], Obsidian Security [S-2026-08-04-obsidian-security-series-d] and Zenity [S-2026-06-08-zenity-least-agency], usually as the only named standard in a release. On 1–2 September 2026 it moved from taxonomy toward tooling: it formally unveiled a 2026 LLM Top 10 whose ranking is for the first time partly weighted on real incident data (6,639 incidents at 25%), accepted the donation of an Agent Control Standard (ACS) — a v0.1 open specification for runtime agent control built on declarative middleware hooks, a Guardian-Agent enforcement model, OpenTelemetry/OCSF tracing and an Agent Bill of Materials — and published a Framework Crosswalk mapping 51 GenAI weaknesses to 25 frameworks including the EU AI Act [S-2026-09-01-owasp-acs-llm-top10-2026]. It matters to this wiki because ACS is the first vendor-neutral attempt to standardise the inspectable / traceable / instrumentable properties that FS assurance of agents will need, and because the Crosswalk is a candidate reverse-lookup from already-evidenced security controls to AI-regulatory coverage — while, per the Cloud Security Alliance, ACS is today “an architecture to plan around and pilot against rather than a control they can deploy” [S-2026-09-01-owasp-acs-llm-top10-2026].

Positions / Claims they advance

  • Agents must be “inspectable, traceable and instrumentable” — visibility into what an agent is, what it can access, what it did and why, and the ability to control it at runtime; ACS “defines how agent platforms expose middleware hooks and how safety policies can be enforced through them”, aiming at “declarative controls that are portable across agent frameworks” [S-2026-09-01-owasp-acs-llm-top10-2026]. (Design intent; v0.1 is definitions and schema only.)
  • Excessive Agency is now the #3 LLM risk, up from #6, on a methodology that weights 6,639 documented incidents at 25% alongside 75% expert consensus; System Prompt Leakage was retired for the broader “Hidden Context Exposure” [S-2026-09-01-owasp-acs-llm-top10-2026] (ranking detail via the CSA note citing OWASP).
  • Security guidance should crosswalk to compliance frameworks — the GenAI Security Industry Framework Crosswalk maps OWASP weaknesses to NIST, ISO, MITRE ATLAS and EU AI Act controls [S-2026-09-01-owasp-acs-llm-top10-2026] (Crosswalk itself not fetched; scope per the AI Pulse relay).
  • An Agent Bill of Materials (AgBOM) in CycloneDX/SPDX/SWID form should expose an agent’s tools, models and accessible data dynamically [S-2026-09-01-owasp-acs-llm-top10-2026].
  • The project is vendor-sponsored (new Gold: F5, WitnessAI; Silver: Evoke Security, Mondoo; Palo Alto Networks and Zenity quoted) — sponsor quotes endorse ACS’s direction; none claims an implementation [S-2026-09-01-owasp-acs-llm-top10-2026].

Relationships

  • relates-to → AI Governance Platforms — ACS is a vendor-neutral candidate for the runtime-control locus that five vendor classes on that page each claim; the Top 10 is the standard most guardrail vendors name [S-2026-09-01-owasp-acs-llm-top10-2026].
  • relates-to → Model Risk Management and Agentic AI — “Excessive Agency” and AgBOM inventory bear on agent permission scoping and inventory expectations under SS1/23 / SR 11-7 [inference].
  • relates-to → Giskard — Giskard markets “OWASP Top 10 LLM compliance packs” for its Guards product (vendor assertion) [S-2026-07-23-giskard-hf-breach-guards].
  • relates-to → Zenity — Zenity’s CTO is quoted in the 2026 release; Zenity’s “least agency” research converges with OWASP agentic guidance [S-2026-09-01-owasp-acs-llm-top10-2026][S-2026-06-08-zenity-least-agency].
  • relates-to → Obsidian Security — Obsidian describes its agent-access controls as “aligned to OWASP standards”, the only standard named in that release [S-2026-08-04-obsidian-security-series-d].
  • relates-to → Palo Alto Networks — Prisma AIRS product VP quoted as a Top 10 contributor and collaborator [S-2026-09-01-owasp-acs-llm-top10-2026].
  • relates-to → EU AI Act — the Framework Crosswalk maps OWASP weaknesses to EU AI Act controls (clause-level fidelity unverified) [S-2026-09-01-owasp-acs-llm-top10-2026].

Tracked changes

  • 2026-08-03 — OWASP GenAI LLM Top 10 2026 published (per CSA note; document not fetched) [S-2026-09-01-owasp-acs-llm-top10-2026].
  • 2026-09-01/02 — Formal unveiling of the 2026 Top 10; Agent Control Standard donated to the project (v0.1 public preview; Apache 2.0 code, CC BY-SA 4.0 docs; roadmap v1 instrumentation and sample Guardian Agent, v2 AgBOM mappers, v3 deny/modify over MCP and A2A); Framework Crosswalk published; AI Security Solutions Directory expanded; four new sponsors; 30,000-member milestone [S-2026-09-01-owasp-acs-llm-top10-2026].
  • 2026-09-04 — Cloud Security Alliance research note assesses the release: “pilot against, don’t deploy” ACS; adoption by framework/platform vendors unresolved [S-2026-09-01-owasp-acs-llm-top10-2026].

Open Questions

  • Who authored and donated ACS, and will any sponsoring vendor, hyperscaler or agent framework (LangGraph, CrewAI, AutoGen, FastMCP, A2A) implement it — or does it compete with Microsoft’s “Agent Control Specification” and proprietary hooks (AWS AgentCore, Credo Agent Governor)? [S-2026-09-01-owasp-acs-llm-top10-2026][S-2026-09-01-microsoft-rai-transparency-report-2026][inference]
  • Would an AgBOM be accepted by a supervisor or ISO/IEC 42001 auditor as the agent-inventory artefact, and how does it reconcile with governance-platform, identity and hyperscaler registries? [inference]
  • Has anyone independently verified the Crosswalk’s EU AI Act mappings at article level? Not fetched; not stated [S-2026-09-01-owasp-acs-llm-top10-2026].
  • When vendors claim “OWASP alignment” (Giskard, Obsidian), which edition and which controls — and does the 2026 re-ranking (Excessive Agency #3) change what such claims should cover? [inference]

Sources