How to Get Involved With the OWASP Gen AI Security Project
You can get involved with the OWASP Gen AI Security Project by joining it as a member, following its What's New, blog, events, and news channels, attending or meeting the project at conferences such as InfoSec World 2026 and OWASP Global AppSec USA 2026, and contributing to its open-source guidance and resources. The project describes itself as a global, community-driven and expert-led initiative that produces freely available open-source guidance for understanding and mitigating security and safety concerns in Generative AI applications and adoption, so participation is aimed at people who want to help build or apply that guidance rather than consume a commercial product.
Ways to Participate
The site presents involvement along a few concrete paths:
- Join as a member. The project's own call to action is "Join Now," and it reports a community that has topped 30,000 members across many countries. Membership is the entry point for the wider community.
- Contribute to open-source guidance and resources. The project frames its output as community-driven guidance and resources, which is where subject-matter contributions land.
- Follow the project's updates. The site maintains What's New, Resources, Blog, Events, and News sections, so you can track releases and activity without committing to a working role first.
- Meet the project in person. It hosts and attends events, including InfoSec World 2026 in Orlando, FL (10/11–10/15), OWASP Global AppSec USA 2026 (11/5–11/6), and the OWASP Gen AI Security Summit, London at Infosec Europe.
What You'd Be Contributing To
Knowing the current output helps you decide where you can add value. The project's recent and featured publications include:
| Resource | What it is |
|---|---|
| OWASP GenAI LLM Top 10 2026 | The latest community-driven guide to the most critical security risks facing applications powered by large language models |
| GenAI Security Industry Framework Crosswalk | An open-source resource connecting OWASP GenAI security risks to established industry security, governance, and compliance frameworks |
| Agent Control Standard (ACS) | A standard aimed at transparency and control for AI agents operating across cloud, SaaS, on-premises, and other environments |
| FinBot CTF | A hands-on Capture-The-Flag environment built around a simulated financial services application, as a companion to the project |
The project also publishes blog analysis from contributors, such as a piece on memory and context poisoning written by a co-lead of the OWASP ASI06: Memory & Context Poisoning entry in the OWASP Top 10 for Agentic Applications.
Who This Suits
Because the initiative is expert-led but community-driven, the fit is broad: security practitioners assessing GenAI and agentic AI risk, developers building LLM-powered applications, governance and compliance staff who need to map AI risk to existing frameworks, and researchers or writers who want to contribute analysis. If your goal is simply to read the guidance, the Resources, Blog, and What's New sections cover that without joining.
Practical Notes
- The project describes its guidance and resources as freely available and open source; the site does not present pricing or paid tiers, and no login requirement is stated for reading its published material.
- Event attendance is separate from membership — conferences like InfoSec World 2026 and OWASP Global AppSec USA 2026 are external OWASP and industry events where the project appears, so check those events' own registration details.
- Start with the resource closest to your work (for example, the LLM Top 10 if you build LLM applications, or the Crosswalk if you handle governance), then use "Join Now" if you want to move from reading to contributing.