OWASP Agentic AI Top 10 Vulnerability Scoring System (AIVSS) & Comprehensive AI Security Framework
This initiative kicks off with the critical development of a rigorous scoring system specifically for the OWASP Agentic AI Top 10. This initial, high-impact deliverable will then expand into a comprehensive Artificial Intelligence Vulnerability Scoring System (AIVSS) Framework Package. The broader project aims to provide a structured and quantifiable methodology to identify, assess, and mitigate vulnerabilities specific to all types of AI systems – not just Large Language Models (LLMs), Generative AI, or Agentic AI. The ultimate goal is a complete AIVSS Framework Package that serves as a baseline for understanding and managing AI security risks across the entire AI landscape.
🚀 Try the AIVSS Calculator Demo
Experience our interactive AIVSS calculator in action! Calculate vulnerability scores, understand security impacts, and generate detailed reports.
Key Deliverables
- Agentic AI Top 10 Vulnerability Scoring System:
- A precise and quantifiable scoring methodology tailored to the unique risks identified in the OWASP Agentic AI Top 10.
- Clear rubrics and guidelines for assessing the severity and exploitability of these specific vulnerabilities.
- Comprehensive AIVSS Framework Package:
- Standardized AIVSS Framework: A scalable framework validated across a diverse range of AI applications, including and extending beyond Agentic AI.
- AIVSS Framework Guide: Detailed documentation explaining the metrics, scoring methodology, and application of the framework.
- AIVSS Scoring Calculator: An open-source tool to automate and standardize the vulnerability scoring process.
- AIVSS Assessment Report Templates: Standardized templates for documenting AI vulnerability assessments.
The Importance of this Top-Level OWASP Project: Meeting Critical Demands in AI Security
This Top-Level OWASP project is strategically established to meet the following critical demands in the rapidly evolving field of Artificial Intelligence security:
- Demand for a Focused Agentic AI Scoring System & Comprehensive AI Vulnerability Quantification: There is an immediate and pressing need for a rigorous scoring system for the OWASP Agentic AI Top 10. Beyond this, the broader AI landscape requires a method to move beyond securing specific implementations and quantify the offensive potential and vulnerabilities inherent in underlying AI technologies themselves. This project directly addresses this fundamental gap.
- Demand for Proactive Measures Against Emerging Threats (Future-Proofing): As AI technology evolves and diversifies (e.g., advancements in Agentic AI), there is a demand for a security framework that can adapt to new models, algorithms, and applications. This project provides such a future-proof approach, ensuring OWASP remains at the forefront of addressing emerging AI threats.
- Demand for Open Collaboration and Knowledge Sharing: Effective AI security requires broad collaboration. This open-source OWASP project fulfills the demand for a platform that fosters knowledge sharing among security professionals, AI researchers, and industry stakeholders across all AI domains.
- Demand for Globally Applicable, Technology-Agnostic Solutions: The security of AI systems is a global concern. This project addresses the demand for a technology-agnostic framework that can achieve wide reach and impact, helping to improve the security of AI systems worldwide.
- Demand for Alignment with OWASP’s Core Mission in the AI Era: OWASP’s mission to secure software must extend to AI. This project directly meets the demand for a framework focused on identifying, assessing, and mitigating vulnerabilities in this increasingly critical technology.
Road Map
The following is the initial roadmap:
- AIVSS Core Definition & Agentic AI Top 10 Scoring (Months 1-3):
- Define core AIVSS metrics, with an initial focus on metrics directly applicable to scoring the OWASP Agentic AI Top 10. Ensure clarity and precision.
- Develop initial scoring rubrics for these Agentic AI-focused metrics.
- AIVSS Framework Specialization & Expansion (Months 4-6):
- Develop specialized scoring rubrics for other specific AI system types (beyond Agentic AI).
- Identify factors unique to each AI type that influence vulnerability assessment.
- Create templates for AIVSS assessment reports, adaptable to different AI system types.
- AIVSS Scoring Calculator Development (Months 7-9):
- Develop the core functionality of the AIVSS scoring calculator, ensuring it supports core AIVSS metrics, Agentic AI Top 10 scoring, and specialized rubrics.
- Implement the ability to add new AIVSS metrics and scoring rubrics.
- AIVSS Tool Testing and Refinement (Months 10-12):
- Test the AIVSS scoring calculator against a diverse set of AI systems (including Agentic AI test cases), generating assessment reports.
- Refine metrics, rubrics, and the calculator based on user feedback and assessment results.
- Documentation and Release (Month 12):
- Finalize the AIVSS Framework Guide (comprehensive, clear, easy to understand).
- Release the AIVSS Scoring Calculator as an open-source project.
- Publish AIVSS assessment report templates and example reports (including for Agentic AI) on the OWASP project website.
- Create detailed project documentation, including an integration guide for existing SDLCs.
Multi-Year Project Roadmap
- Year 2: Apply AIVSS to Financial and Healthcare Industries:
- Develop industry-specific guidelines for applying AIVSS to AI systems in finance and healthcare.
- Create case studies and assessment reports showcasing AIVSS application in these sectors.
- Collaborate with industry experts for validation and alignment with best practices.
- Year 2/3: Expand AIVSS for Emerging AI Threats:
- Continuously update the AIVSS framework to address new AI security threats, including further evolutions in Agentic AI vulnerabilities beyond the initial Top 10.
- Develop new AIVSS metrics and scoring rubrics as needed.
- Year 3+: AIVSS Certification Program:
- Explore creating a certification program for professionals proficient in using the AIVSS framework to drive adoption and enhance AI security expertise.
Leadership & Founding Members
Project Leadership
Current Leaders

Ken Huang - Project Lead

Michael Bargury - Project Lead

Vineeth Sai Narajala - Project Lead
Founding Members
Names are listed alphabetically by last name.
The OWASP AIVSS project was established through the collaborative efforts of security experts and AI specialists who recognized the need for a standardized vulnerability scoring system for AI systems. We are grateful to the following founding members for their contributions:

Sunil Agrawal
Chief Information Security Officer
Glean

David Ames
Partner
PwC

Michael Bargury
Founder and CTO
Zenity

Manish Bhatt
Security Researcher
Amazon Kuiper Security

Mark Breitenbach
Senior Security Engineer
Dropbox

Anat Bremler-Barr
Professor of Computer Science
Tel Aviv University

Siah Burke
HIPAA Security Officer
Siah.ai

David Campbell
AI Security
Scale AI

Ying-Jung Chen
AI safety researcher, PhD
Georgia Institute of Technology

Anton Chuvakin
Security Solution Strategy
Google

Jason Clinton
CISO
Anthorphic

Adam Dawson
Staff AI Security Researcher
Dreadnode

Ron F. Del Rosario
VP-Head of AI Security
SAP

Walker Lee Dimon
AI Security Researcher
MITRE

Marissa Dotter
AI Security Researcher
MITRE

Leon Derczynski
Principal Research Scientist
NVIDIA

David Haber
CEO
Lakera

Idan Habler
Staff AI/ML Security Researcher
Intuit

Jason Haddix
Founder
Arcanum Information Security

Keith Hoodlet
Director of Product Security
Thinkst Canary

Ken Huang
AIVSS Project Lead
OWASP

Chris Hughes
CEO
Aquia

Charles Iheagwara
AI/ML Security Leader
AstraZeneca

Krystal Jackson
Researcher
Center for Long-Term Cybersecurity, UC Berkeley

Diana Kelley
CISO
Protect AI

Sushmitha Janapareddy
Director - Security Integrations
American Express

Rob Joyce
Former Cybersecurity Director of NSA, Advisor to PwC
PwC

Prashant Kulkarni
Lead AI Security Research Engineer
Google Cloud

Mahesh Lambe
Founder
MIT, Unify Dynamics

Edward Lee
Vice President, Lead AI Security
JP Morgan

Nate Lee
CEO
Cloudsec.ai

Vishwas Manral
CEO
Precize.ai

Daniela Muhaj
Executive-in-Residence for Research & Development
AI 2030

Om Narayan
AI Security Researcher
AWS

Vineeth Sai Narajala
Application Security
AWS

Advait Patel
Senior Site Reliability Engineer (DevSecOps \+ Cloud \+ AIOps)
Broadcom, IEEE

Alex Polyakov
CEO
adversa.ai

Ramesh Raskar
Professor & Director
MIT Media Lab

Tal Shapira
Co-Founder & CTO
Reco AI

Akram Sheriff
Senior AI/ML Software Engineering Leader
Cisco

Samantha Siau
Security and Compliance
Anthropic

Kevin Simmonds
Partner on AI Offensive Security
PWC

Martin Stanley
NIST AI RMF Lead
Independent

Omar A. Turner
General Manager of Security
Microsoft

Apostol Vassilev
AI Research Team Supervisor
NIST

David Webb
Agency Cybersecurity Officer
Cybersecurity and Infrastructure Security Agency

Dennis Xu
Research VP, AI
Gartner

Xiaochen Zhang
Executive Director and Chief Responsible AI Officer
AI 2030
Recognition
We extend our gratitude to all founding members who have contributed to establishing this crucial framework for AI security assessment. Their vision and dedication have been instrumental in shaping the AIVSS project.
Get Involved
Interested in contributing to the AIVSS project? We welcome new contributors and leaders. Please see our Contribution Guidelines for more information on how to get involved.
AIVSS Calculator Demo
Try the AIVSS Calculator
Experience the AIVSS scoring system in action with our interactive calculator. This demo allows you to:
- Calculate vulnerability scores for AI systems
- Understand the impact of different security factors
- Generate detailed reports based on your inputs
Announcements
Stay tuned for the latest updates and announcements regarding the OWASP AIVSS project.
Our initial upcoming release is The OWASP Agentic AI Top 10 Risks and AIVSS-Agentic Scoring System
Publications
Find a curated list of publications, research papers, and articles related to the OWASP AIVSS project and AI vulnerability scoring here.
Our initial upcoming release is The OWASP Agentic AI Top 10 Risks and AIVSS-Agentic Scoring System