Identifying and tackling the risks of Gen AI systems and applications

OWASP GenAI Security Project

A global community-driven and expert led initiative to create freely available open source guidance and resources for understanding and mitigating security and safety concerns for Generative AI  applications and adoption.

Members
k+
Countries
+
AI Cybersecurity Publications
+

What’s New

GenAI Security Industry Framework Crosswalk

The OWASP GenAI Security Project Crosswalk is an open-source resource that connects OWASP GenAI security risks to established industry security, governance, and compliance frameworks. It maps

Agent Control Standard (ACS)

Widescale adoption of AI agents depends on trust, and trust requires transparency and control. Enterprises cannot rely on black-box agents operating across cloud, SaaS, on-premises and

OWASP GenAI LLM Top 10 2026

OWASP Top 10 for LLM Applications 2026 is the latest community-driven guide to the most critical security risks facing applications powered by large language models. Developed

OWASP GenAI Security Project Unveils 2026 Top 10 for LLM Applications, New Agent Control Standard and Sponsors as Community Tops 30,000 Members

OWASP GenAI Security Project Releases 2026 Top 10 for LLM Applications, Debuts Agent Control Standard and New Resources for Securing Generative and Agentic AI F5, WitnessAI,

Memory Is a Feature. It Is Also an Attack Surface

As co-lead of OWASP ASI06: Memory & Context Poisoning entry as part of OWASP Top 10 for Agentic Applications , I have spent a lot of

FinBot CTF Is Live: A Hands-On Companion to the OWASP GenAI Security Project

FinBot is a hands-on companion to the OWASP GenAI Security Project, offering an interactive Capture-The-Flag environment built around a simulated financial services application. Designed as the

OWASP Global AppSec USA 2026

From November 5–6, 2026, connect with over 800 hundred security experts, thought leaders, and practitioners. Be a part of something extraordinary at the OWASP Global AppSec

InfoSecWorld 2026

InfoSec World brings together cybersecurity leaders and practitioners who are responsible for protecting modern organizations while enabling business growth. Through expert-led sessions, hands-on learning, and meaningful

OWASP Gen AI Security Summit, London at Infosec Europe

Join the OWASP GenAI Security Project for a half-day summit on Thursday 4th June at Infosecurity Europe 2026, where global project leaders, industry practitioners and regulatory

OWASP Top 10 Risks for Large Language Models: 2025 updates

OWASP Warns of Growing Data Exposure Risk from AI in New Top 10 List for LLMs

OWASP Top 10 for LLM and new tooling guidance targets GenAl security

Be in the know! Join the Newsletter.
Get updates on tools, threat intel, community heighlights, and new initiatives – straight to your inbox.

Affiliated Standards Organizations and Projects

Our Initiatives

Top 10 for LLM and GenAI

Key security risks for GenAI and LLM-based applications.

AI Threat Intelligence and Response

Tracks GenAI misuse by attackers and emerging threat patterns.

AI Security Governance

Best practices & frameworks for responsible GenAI program oversight.

AI Bill of Materials

Standards and tooling to address AI supply chain security

Agentic App Security

Securing autonomous agents and multi-step AI workflows.

Data Security

Protects training and retrieval data from leaks and tampering.

Red Teaming
& Evaluation

Testing GenAI systems through adversarial red teaming methods.

AI Security Solutions

Tools and platforms to address top GenAI security risks.

What the Industry is saying

OWASP Gen AI Security Project Sponsors

GenAI-SecurityProject-SponsorBadgeGOLD-Rectangular
GenAI-SecurityProject-SponsorBadgeGOLD-Rectangular-white

Events

OWASP Global AppSec USA 2026

From November 5–6, 2026, connect with over 800 hundred security experts, thought leaders, and practitioners. Be a part of something extraordinary at the OWASP Global AppSec US Conference, OWASP’s

InfoSecWorld 2026

InfoSec World brings together cybersecurity leaders and practitioners who are responsible for protecting modern organizations while enabling business growth. Through expert-led sessions, hands-on learning, and meaningful peer connection, attendees

OWASP Gen AI Security Summit, London at Infosec Europe

Join the OWASP GenAI Security Project for a half-day summit on Thursday 4th June at Infosecurity Europe 2026, where global project leaders, industry practitioners and regulatory experts will present

Gen AI Project Application Security & Risk Virtual Summit

Generative and agentic AI are transforming how applications are built, deployed and operated but they are also expanding the attack surface in ways traditional AppSec programs were never designed

200+ Supporting Organizations

Scroll to Top

Home