OWASP GenAI Security Project’s cover photo
OWASP GenAI Security Project

OWASP GenAI Security Project

Data Security Software Products

Wakefield, Mass 31,481 followers

Evolving Security For Generative AI

About us

The OWASP Gen AI Security Project is a global, open-source initiative dedicated to identifying, mitigating, and documenting security and safety risks associated with generative AI technologies, including large language models (LLMs), agentic AI systems, and AI-driven applications. Our mission is to empower organizations, security professionals, AI practitioners, and policymakers with comprehensive, actionable guidance and tools to ensure the secure development, deployment, and governance of generative AI systems. refined by dedicated sub-teams and subjected to public review. The OWASP Gen AI Security Project welcomes contributors from around the world. Whether you’re an AI researcher, security expert, or industry professional, you can help advance AI security by: - Contributing to research and documentation efforts. - Participating in working groups and discussions. - Providing real-world case studies and mitigation strategies. - Supporting localization efforts to expand access to AI security guidance. Join us in shaping the future of secure generative AI development. Visit our project page, engage with the community, and help drive the evolution of AI security best practices.

Website
https://genai.owasp.org
Industry
Data Security Software Products
Company size
2-10 employees
Headquarters
Wakefield, Mass
Type
Nonprofit
Founded
2023

Locations

Employees at OWASP GenAI Security Project

Updates

  • Supply Chain, Vibe Coding and the Five Eyes No, that’s not the set-up for a cybersecurity joke. It’s one of the latest episodes of The Threat Intelligence Podcast! 🎙️ 🎧 As part of OWASP’s Gen AI Security Project Threat Intelligence Initiative, hosts Rachel James and Dr. Bryan Nakayama unpack why supply chain attacks are exploding in the age of vibe coding – when AI writes code faster than anyone can security-review it. They walk through recent incidents: the "Cordyceps" CI/CD pipeline flaw affecting Microsoft, Google, Apache and others; the "Miasma" worm that hijacks AI coding assistants at the tool level; and a North Korean actor using a Claude-powered agent to inject a malicious dependency that led to $12M in stolen crypto. 🔗 Listen here: https://lnkd.in/e3PHPAJH #AISecurity #CyberSecurity #GenAISecurityProject #SupplyChainSecurity #VibeCoding

  • We’re connecting the "what can go wrong" with the "what we should do about it." In other words, we've created a practical checklist aligning OWASP's Top 10 agentic AI risks with AIUC-1 security requirements. The AIUC-1 Crosswalk provides a bidirectional mapping between AIUC-1 requirements and the OWASP Agentic Security Initiative's Top 10 risks for autonomous AI systems, helping organizations connect security controls with real-world threats. It covers risks such as agent goal hijacking, tool misuse, identity and privilege abuse, memory poisoning, insecure inter-agent communication, cascading failures, trust exploitation, and rogue agents. Whether you're implementing AIUC-1 or using the OWASP Top 10 as your guide, the crosswalk makes it easier to identify relevant controls and risk coverage. It also highlights eight priority gaps where AIUC-1 could be expanded, including agent identity, runtime containment, architectural monitoring, supply chain attestation and schema controls. The result is a stronger bridge between AI governance, security, safety and reliability frameworks for the next generation of agentic AI. Check below to get your copy! #OWASP #AIsecurity #AgenticAI #GenAISecurityProject

    • No alternative text description for this image
  • 🚨 The GenAI Project Application Security & Risk Virtual Summit is now live on YouTube! 🚨 This virtual summit, presented in partnership with the OWASP GenAI Security Project, brought together 100s of CISOs, security practitioners and builders to tackle one urgent question: How do we secure AI systems before risk outpaces adoption? We've recorded 20 sessions across three tracks: agentic security, AI red teaming & threat intel, and GenAI adoption & governance. The summit explores how enterprises are embedding AI risk into governance frameworks, evolving adversarial testing for agentic systems and designing secure-by-default architectures for autonomous applications. Visit the playlist to get started! 🔗👇 #GenAI #AIsecurity #OWASP #AIgovernance #GenAISecurityProject

    • No alternative text description for this image
  • Fun times at BrewDog last night! One of the best parts of conferences like Black Hat is the opportunity to connect with peers, practitioners and industry experts outside the conference halls. The OWASP GenAI Security Project hosted a casual meetup to continue the conversation around the future of AI security, exchange ideas, and strengthen connections within the community. A big thank you to Zenity for sponsoring the event and to all of our gold and silver sponsors who help make the work of this project possible. Looking forward to more great discussions throughout the week! #BlackHat #OWASP #AIsecurity #GenAI #security #GenAISecurityProject

  • If you’re attending Black Hat and/or DEF CON 34, don’t miss the OWASP GenAi Security Project sessions featuring cybersecurity industry veterans saikishu (Venkata Sai Kishore Modalavalas), Helen Oakley and Dmitry Raidman. Join us for three impactful trainings: 👉 “FinBot CTF: Hands-On Agentic AI Threats” (12:45-13:45) 👉 “OWASP AIBOM Generator” (14:00-15:00) 👉 "No Jailbreak Required: Pwning AI Agents Through the Tools They Trust" (16:50-17:20) Date: August 8 Location: Appsec Village Our presenters: 🔹 Helen Oakley, a cybersecurity and AI visionary, shaping secure technological trends across the industry. 🔹 Saikishu (Venkata Sai Kishore Modalavalasa): Chief Architect & Engineering Leader at @Straiker, building AI security products for AI-native apps at scale. 🔹 Dmitry Raidman, the co-founder and CTO of CyBeats, leads product and technology strategy focused on software supply chain security, SBOM management and product security compliance 🔗 https://lnkd.in/eNe9yxpH 🔗 https://lnkd.in/e3tKX53i 🔗 https://lnkd.in/efXidYdQ #BlackHat #DEFCON #OWASP #AIsecurity

    • No alternative text description for this image
  • 🚨 **It's Here: The New OWASP GenAI LLM Top 10 for 2026 Has Arrived.** The list that helped kickstart defining GenAI and LLMs security is back with an update for 2026. The the guidance that started the global conversation around securing LLMs and Generative AI, is now available with updated rankings, new insights, and revised guidance reflecting today's rapidly evolving GenAI threat landscape. Whether you're building, deploying, governing, or securing AI applications, this is essential reading. ✅ Updated risk rankings ✅ Refined guidance and mitigations ✅ Reflects the latest real-world threats facing LLM and GenAI applications A huge thank you to the hundreds of security researchers, practitioners, developers, AI experts, and reviewers from around the world who contributed their time, expertise, and thoughtful feedback to make this latest release possible. This guide is a testament to the strength of the global open-source security community and the collaborative spirit that drives the GenAI Security Project. 📥 **Download the new OWASP Top 10 for LLMs:** 🔗 https://lnkd.in/eyZpPWD3 🌐 **Learn more about the OWASP GenAI Security Project and explore additional guidance, frameworks, and tools:** 🔗 https://genai.owasp.org/ Join thousands of security professionals, developers, architects, and AI leaders using the OWASP GenAI Security Project as the foundation for secure AI adoption. Become a contributor yourself. #OWASP #GenAI #AISecurity #LLMSecurity #ArtificialIntelligence #CyberSecurity #SecureAI #AppSec #DevSecOps #RiskManagement #LLM #GenerativeAI #AIGovernance #GenAISecurityProject

    • No alternative text description for this image
  • 🌐 600+ experts. 18+ countries. Nearly 25,000 community members. One mission: make AI security accessible to everyone. The OWASP GenAI Security Project started in 2023 as a small group of security researchers tackling an urgent gap: no established frameworks for securing LLM applications. What followed was one of the fastest-growing open-source security communities in the world. Today, the project delivers: 🔹 The OWASP Top 10 for LLMs — the industry standard for GenAI application security risk 🔹 The OWASP Top 10 for Agentic Applications — peer-reviewed guidance for autonomous AI systems 🔹 MCP security guides for both server development and safe use of third-party servers 🔹 AI Security Solutions Landscapes for LLMs and Agentic AI 🔹 GenAI Data Security, Red Teaming, Incident Response, and AIBOM resources 🔹 Translations in 8+ languages to support global adoption Everything the project produces is open source, vendor-neutral, and built by practitioners for practitioners. If you work in AppSec, AI development, or security leadership and haven't connected with this community yet, now is the time. 👉 Explore all resources: 🔗 https://lnkd.in/g9NZGAmD 👉 Get involved: 🔗 https://lnkd.in/eDGxCxrV #OWASP #GenAI #AISecurity #AgenticAI #LLMSecurity #AppSec #DevSecOps #OpenSource #CyberSecurity

    • No alternative text description for this image
  • 🎊 Join OWASP GenAI Security Project and the broader AI security community for a casual networking evening in Las Vegas! 🎊 Are you attending Black Hat or BSides? If so, don’t miss this chance to meet with OWASP Project Initiative leaders, interact with agentic security experts, and network with community members and peers about the future of AI security. Enjoy great food and drinks with us in a relaxed setting. 🪩 Date: Tuesday, August 4, 2026 🪩 Time: 5:00 PM – 7:00 PM PDT 🪩 Location: BrewDog Las Vegas 🪩 Special thanks to @Zenity for sponsoring this event Admission is free, but space is limited. Please RSVP to secure your spot! See below for the registration link.

    • No alternative text description for this image
  • Is AI really creating super hackers? What the evidence actually shows. In Episode 4 of the OWASP GenAI Security Project Threat Intelligence Podcast, Rachel James and Dr. Bryan Nakayama examine one of cybersecurity's biggest questions using newly published, empirical research analyzing tens of thousands of criminal forum discussions. Rather than speculating, our experts explore: 🔍 What threat actors are actually saying about AI 🔍 Where large language models are helping attackers today 🔍 Why many of the biggest fears surrounding ai-powered cybercrime have yet to materialize If you're a threat intelligence analyst, SOC leader, CISO, security researcher or AI security practitioner, this episode provides a practical, evidence-based perspective that cuts through the hype. While you’re there, subscribe for future episodes covering the latest developments in AI threat intelligence, adversary behavior and emerging risks. Get the link below. #SOC #AIrisk #OWASP #CISO #AIsecurity

    • No alternative text description for this image
  • 🤔 Have you downloaded your copy of the AI Security Solutions Landscape for Agentic AI Q2 2026? The Solutions Landscape monitors and maps the full Agentic AI lifecycle, focusing on the DevOps–SecOps intersection to meet evolving security needs. Guided by the Agentic AI Threats and Mitigations guide and SecOps tasks, it highlights open-source and commercial solutions by stage, identifying their coverage of Agentic SecOps duties and threat mitigation, and leverages industry and community input as a peer-reviewed resource for navigating agentic AI’s shifting security challenges. Inside the Solutions Landscape, you’ll find: 🔹 The OWASP Agentic AI SecOps framework 🔹 Which solution providers have Agentic taxonomy reporting & support built into their products 🔹 How SecOps and DevOps work together throughout each phase of Agentic AI Get the OWASP “cheat sheet” for better Agentic AI security: 👇

    • No alternative text description for this image

Similar pages

Browse jobs