What Is the OWASP Gen AI Security Project Website?

genai.owasp.org is the home of the OWASP GenAI Security Project, a global, community-driven and expert-led initiative that produces freely available open-source guidance for understanding and mitigating the security and safety risks of generative AI systems and applications. It is the site to use if you need vendor-neutral, community-reviewed material on GenAI and agentic AI security — for example, when threat-modeling an LLM-backed feature, building an AI governance checklist, or briefing a security team. It is not a commercial product page and not a substitute for your own risk assessment.

What the project is

The site describes the initiative as:

  • Global and community-driven — contributors span many countries, and the project reports a community in the tens of thousands of members.
  • Expert-led — content is developed by practitioners rather than published as a single vendor's opinion.
  • Open source and freely available — the guidance and resources are published for anyone to read and reuse.
  • Focused on GenAI security and safety — the scope covers both security concerns and broader safety concerns around generative AI adoption.

What you can find there

The site organizes its output into a few recurring categories.

Category What it covers Example from the site
Top 10 risk lists The most critical security risks for a given class of AI system OWASP Top 10 for LLM Applications 2026; OWASP Top 10 for Agentic Applications
Standards and controls Requirements for controlling how AI systems behave Agent Control Standard (ACS)
Framework mapping Links between OWASP GenAI risks and other governance/compliance frameworks GenAI Security Industry Framework Crosswalk
Hands-on practice Interactive environments for testing skills FinBot CTF, a capture-the-flag built around a simulated financial services application
Blog, news, events Project announcements, technical write-ups, and conference appearances Posts such as "Memory Is a Feature. It Is Also an Attack Surface"; InfoSec World 2026 and OWASP Global AppSec USA 2026

The flagship resources

OWASP Top 10 for LLM Applications 2026 is described as the latest community-driven guide to the most critical security risks facing applications powered by large language models. Use it as a starting taxonomy when scoping an LLM application's threat model.

Agent Control Standard (ACS) addresses trust in AI agents. The site's framing is that widescale adoption of agents depends on trust, and trust requires transparency and control — enterprises cannot rely on black-box agents operating across cloud, SaaS, and on-premises environments. Use it when you need to define what an agent must expose or how it must be constrained before it is allowed to act.

GenAI Security Industry Framework Crosswalk connects OWASP GenAI security risks to established industry security, governance, and compliance frameworks. Use it when you already report against another framework and need to show where GenAI risks fit rather than maintaining a separate list.

How to use the site

  1. Start with the risk list that matches your system. If you are building on an LLM, begin with the Top 10 for LLM Applications. If you are deploying autonomous or semi-autonomous agents, look at the agentic list and the Agent Control Standard.
  2. Map to your existing program. Pull the Crosswalk to translate OWASP risk entries into the governance or compliance framework your organization already uses.
  3. Test understanding. The FinBot CTF provides a simulated environment for practicing against GenAI security issues rather than only reading about them.
  4. Follow changes. The blog, news, and events sections carry releases and technical discussion; the project also appears at conferences such as InfoSec World and OWASP Global AppSec.

What it is not

  • It is not a certification body or an audit standard you can be "compliant" with in a formal regulatory sense.
  • It is not a product, and the site does not present itself as a paid service.
  • It is not a replacement for legal, compliance, or risk decisions specific to your organization — treat the material as input to those decisions.

Joining the community

The site invites participation through a "Join Now" path and lists members, countries, and publications as community metrics. If you want to contribute guidance, review drafts, or follow releases, that is the entry point.

genai.owasp.org
Identifying and tackling the risks of Gen AI systems and applications OWASP GenAI Security Project A global community-driven and expert led initiativ…