What Resources and Standards Does the OWASP Gen AI Security Project Publish?

The OWASP Gen AI Security Project publishes freely available, open-source guidance for understanding and mitigating security and safety concerns in generative AI applications. Its flagship resources are the OWASP GenAI LLM Top 10 2026, the Agent Control Standard (ACS), and the GenAI Security Industry Framework Crosswalk, supported by blogs, events, news, and hands-on training material. These resources suit security engineers, architects, governance and compliance teams, and anyone adopting LLMs or AI agents who needs a structured way to identify and prioritize risk.

The three core publications

OWASP GenAI LLM Top 10 2026

The OWASP Top 10 for LLM Applications 2026 is described as the latest community-driven guide to the most critical security risks facing applications powered by large language models. Use it as a starting point when you need to enumerate and prioritize the risks specific to an LLM-powered application, rather than generic web application risks.

Agent Control Standard (ACS)

The ACS addresses a different problem: trust in AI agents. The project's framing is that widescale adoption of AI agents depends on trust, and trust requires transparency and control — enterprises cannot rely on black-box agents operating across cloud, SaaS, and on-premises environments. Reach for the ACS when your concern is governing what an autonomous or semi-autonomous agent is allowed to do, and how that behavior is made visible and controllable.

GenAI Security Industry Framework Crosswalk

The Crosswalk is an open-source resource that connects OWASP GenAI security risks to established industry security, governance, and compliance frameworks. It is the mapping layer: if you already work within an existing framework and need to show where GenAI risks fit into it, this is the document that saves you rebuilding that mapping yourself.

Resource Problem it solves Best fit
GenAI LLM Top 10 2026 Which risks matter most for LLM-powered applications Application security teams doing risk assessment
Agent Control Standard (ACS) Transparency and control over AI agents across environments Teams deploying or governing AI agents
GenAI Security Industry Framework Crosswalk Aligning GenAI risks with existing security, governance, and compliance frameworks Governance, risk, and compliance functions

Beyond the standards: blogs, events, and hands-on material

The site also carries a blog, an events section, and news. Two examples show the range:

  • Memory & Context Poisoning — a blog post written by a co-lead of the OWASP ASI06 entry in the OWASP Top 10 for Agentic Applications, discussing memory as both a feature and an attack surface.
  • FinBot CTF — a hands-on Capture-The-Flag environment built around a simulated financial services application, positioned as an interactive companion to the project.

If you learn better by doing than by reading, the FinBot CTF is the practical entry point; if you want current thinking on emerging agent risks, the blog is where those discussions appear first.

Community and events

The project describes itself as a global, community-driven and expert-led initiative with members and countries counted in the thousands and a growing set of AI cybersecurity publications. It also lists affiliated standards organizations and projects, and upcoming events including OWASP Global AppSec USA 2026 (November 5–6, 2026), InfoSec World 2026, and the OWASP Gen AI Security Summit in London at Infosec Europe.

How to choose where to start

  • Assessing an LLM application's risk surface → start with the GenAI LLM Top 10 2026.
  • Deploying or governing AI agents → start with the Agent Control Standard.
  • Mapping GenAI risk into an existing compliance or governance program → start with the Crosswalk.
  • Wanting practical, hands-on exposure → try the FinBot CTF.
  • Tracking emerging issues → follow the blog and events.

All of these are published as freely available open-source guidance, so you can download and use them without a commercial relationship with the project.

genai.owasp.org
Identifying and tackling the risks of Gen AI systems and applications OWASP GenAI Security Project A global community-driven and expert led initiativ…