🌐
OWASP
genai.owasp.org › home › resources › llm applications cybersecurity and governance checklist v1.1 – english
LLM Applications Cybersecurity and Governance Checklist v1.1 - English - OWASP Gen AI Security Project
April 28, 2025 - GOVERNANCE CHECKLIST · Threat Intelligence · AGENTIC APP SECURITY · Secure AI Adoption · AI Red Teaming · Data Security · BLOG · ABOUT · Mission and Charter · Governance · LEADERSHIP · INDUSTRY RECOGNITION · CONTRIBUTORS · SPONSORS · SUPPORTERS · SPONSORSHIP · NEWSROOM · CONTACT · BRANDING · GEN AI SECURITY · resources · Whitepapers/Guides · May 7, 2024 · The OWASP Top 10 for LLM Applications Cybersecurity and Governance Checklist is for leaders across executive, tech, cybersecurity, privacy, compliance, and legal areas, DevSecOps, MLSecOps, and Cybersecurity teams and defenders.
🌐
OWASP
owasp.org › www-project-ai-testing-guide
OWASP AI Testing Guide | OWASP Foundation
The OWASP AI Testing Guide fills this gap by establishing a practical standard for trustworthiness testing of AI systems, offering a unified, technology-agnostic methodology that evaluates not only security threats but the broader trustworthiness ...
Discussions

A Complete Penetration Testing & Hacking Tools List for Hackers & Security Professionals
Mods should sidebar this it add this to a subreddit wiki More on reddit.com
🌐 r/HowToHack
80
738
January 31, 2020
Is there a security checklist I can use to make sure my CRUD API is reasonably secure?
https://owasp.org/API-Security/editions/2023/en/0x11-t10/ More on reddit.com
🌐 r/golang
15
57
May 8, 2024
Application Security Checklist
Check out ASVS The OWASP Application Security Verification Standard (ASVS) Project provides a basis for testing web application technical security controls and also provides developers with a list of requirements for secure development. https://owasp.org/www-project-application-security-verification-standard/ More on reddit.com
🌐 r/cybersecurity
4
4
April 26, 2024
[deleted by user]
Use a SAST tool. You are taking on too much accountability doing it manually. More on reddit.com
🌐 r/cybersecurity
55
97
January 3, 2024
🌐
OWASP
owasp.org › www-project-artificial-intelligence-security-verification-standard-aisvs-docs
OWASP Artificial Intelligence Security Verification Standard AISVS Docs | OWASP Foundation
This site is the public documentation wrapper for the main OWASP/AISVS content repository. Design. Use it as a security checklist when architecting AI systems.
🌐
DEV Community
dev.to › alessandro_pignati › the-owasp-top-10-for-ai-agents-your-2026-security-checklist-asi-top-10-cck
The OWASP Top 10 for AI Agents: Your 2026 Security Checklist (ASI Top 10) - DEV Community
December 30, 2025 - The OWASP ASI Top 10 is here. Learn the 10 biggest threats to autonomous AI agents, from Goal Hijack to Rogue Agents, and how to secure your code against the next generation of attacks.
🌐
Owaspai
owaspai.org › docs › ai_security_overview
0. AI Security Overview – AI Exchange
The OWASP GenAI Security Project is an umbrella project of various initiatives that publish documents on Generative AI security, including the LLM AI Security & Governance Checklist and the LLM top 10 - featuring the most severe security risks of Large Language Models.
🌐
OWASP Cheat Sheet Series
cheatsheetseries.owasp.org › cheatsheets › AI_Agent_Security_Cheat_Sheet.html
AI Agent Security - OWASP Cheat Sheet Series
This cheat sheet provides best practices to secure AI agent architectures and minimize attack surfaces.
🌐
GitHub
github.com › OWASP › AISVS
GitHub - OWASP/AISVS: The AI Security Verification Standard (AISVS) focuses on providing developers, architects, and security professionals with a structured checklist to verify the security of AI-driven applications. · GitHub
April 28, 2026 - The AI Security Verification Standard (AISVS) focuses on providing developers, architects, and security professionals with a structured checklist to verify the security of AI-driven applications. - OWASP/AISVS
Starred by 331 users
Forked by 93 users
🌐
byteiota
byteiota.com › home › news & analysis › news › owasp aisvs 1.0: the ai security checklist developers need
OWASP AISVS 1.0: The AI Security Checklist Developers Need | byteiota
June 15, 2026 - The 14 chapters span the full AI lifecycle: training data integrity, input validation, model lifecycle, infrastructure, access control, supply chain, model behavior, memory and vector databases, agentic orchestration, MCP security, adversarial robustness, privacy, monitoring and logging, and human oversight.
Find elsewhere
🌐
OWASP
genai.owasp.org › home
Home - OWASP Gen AI Security Project
1 month ago - The State of Agentic AI Security and Governance provides a comprehensive view of today’s landscape for securing and governing autonomous AI systems. It explores the frameworks, ... The AIUC-1 Crosswalk of the OWASP Top 10 for Agentic Applications provides a bidirectional mapping between AIUC-1 requirements and the OWASP Agentic Security Initiative’s Top 10
🌐
OWASP
owasp.org › www-project-ai-security-and-privacy-guide
OWASP AI Exchange | OWASP Foundation
Guidance on designing, creating, testing, and procuring secure and privacy-preserving AI systems
🌐
Iternal Technologies
iternal.ai › home › ai agent security checklist
AI Agent Security Checklist (2026): Agentic Risks & Controls
May 30, 2026 - An AI agent security checklist covers autonomous, tool-using, stateful systems -- not just a model that generates text. It adds controls absent from an LLM checklist: agent inventory and discovery, non-human identity and least-privilege tool ...
🌐
Infosecurity Magazine
infosecurity-magazine.com › news › owasp-security-checklist
OWASP Releases Security Checklist Generative AI Deployment - Infosecurity Magazine
March 11, 2026 - This 32-page document is designed to help organizations create a strategy for implementing large language models (LLMs) and mitigate the risks associated with the use of these AI tools. Sandy Dunn, chief information security (CISO) at Quark IQ and lead author of the checklist, began work on it in August 2023 as an additional supporting resource to OWASP’s Top 10 Security Issues for LLM Applications, published in the summer of 2023.
🌐
ReversingLabs
reversinglabs.com › blog › owasp-llm-ai-security-governance-checklist-13-action-items-for-your-team
OWASP's LLM AI Security & Governance Checklist: 13 action items for your team | RL Blog
July 31, 2025 - This complexity necessitates a ... Lau · The new OWASP LLM AI Security & Governance Checklist (PDF) is organized into 13 areas of analysis....
🌐
AI Buzz
aibuzz.blog › home › 80. owasp ai testing guide v1 explained: a practical standard for testing ai trustworthiness (with a copy/paste test plan)
OWASP AI Testing Guide 2026: Checklist, Tools & 5 Steps
The OWASP AITG’s first and most consequential contribution is codifying this difference: AI systems require a testing discipline that evaluates trustworthiness properties — fairness, reliability, transparency, and safety — alongside the ...
Published   May 31, 2026
🌐
SPHR
sphr.world › home › blog › owasp's agentic top 10: a production checklist for ai agents
OWASP Agentic AI Top 10 (2026): Production Checklist — SPHR
1 week ago - The OWASP Top 10 for Agentic Applications 2026 is the current edition, published on December 9, 2025 by the OWASP GenAI Security Project, and it uses the identifiers ASI01 through ASI10. It is a distinct release from the earlier OWASP Top 10 for LLM Applications, and the 2026 edition formalizes the agentic-skills behavior layer as a vulnerable component and the Least-Agency principle — granting an agent only the minimum autonomy its task needs. It is the version this checklist maps to.
🌐
OWASP
genai.owasp.org › home › resources › owasp top 10 for agentic applications for 2026
OWASP Top 10 for Agentic Applications for 2026 - OWASP Gen AI Security Project
December 10, 2025 - The OWASP Top 10 for Agentic Applications 2026 is a globally peer-reviewed framework that identifies the most critical security risks facing autonomous and agentic AI systems. Developed through extensive collaboration with more than 100 industry experts, researchers, and practitioners, the list provides practical, actionable guidance to help organizations secure AI agents that plan, act, and make decisions across complex workflows.
🌐
Thomas Murray
cyber.thomasmurray.com › insights › ai-cyber-security-checklist-owasp-ai-top-10
AI Cyber Security Checklist: OWASP AI Top 10 | Thomas Murray Cyber Risk
October 9, 2025 - This checklist, mapped to the OWASP AI Top 10, helps you assess and strengthen your organisation’s defences against AI-related security, privacy, and compliance risks.
Address   77-85 Fulham Palace Road, W6 8JA, Smiths Square
🌐
OWASP
owasp.org › www-project-top-10-for-large-language-model-applications
OWASP Top 10 for Large Language Model Applications | OWASP Foundation
This is the repository for the OWASP Top 10 for Large Language Model Applications. However, this project has now grown into the comprehensive OWASP GenAI Security Project - a global initiative that encompasses multiple security initiatives beyond just the Top 10 list.
🌐
Aisecurityandsafety
aisecurityandsafety.org › home › guides › owasp top 10 for ai & llm applications: summary & implementation guide
OWASP Top 10 for AI & LLM Applications: Summary & Implementation Guide | AI Safety Directory
March 16, 2026 - Mitigate with retrieval-augmented generation for factual grounding, confidence scoring, citation verification, and clear disclaimers about AI limitations. LLM10 — Unbounded Consumption / Denial of Service: Adversaries can abuse LLM resources ...
🌐
Alexewerlof
blog.alexewerlof.com › alex ewerlöf notes › owasp top 10 agents & ai vulnerabilities (2026 cheat sheet)
OWASP Top 10 Agents & AI Vulnerabilities (2026 Cheat Sheet)
March 20, 2026 - Verifiability (Observability): You cannot secure what you cannot see. Log the exact prompt sent to the LLM, the exact output received, the tool selection rationale, and the parameters. Implement “Shadow Mode” testing where the agent plans actions but cannot execute them without human review until trust is established. Charity Majors recently wrote a post that nails that last point. AI engineering is not magic; it is distributed systems engineering with a highly unreliable component in the middle.