OWASP/AISVS

The AI Security Verification Standard (AISVS) focuses on providing developers, architects, and security professionals with a structured checklist to verify the security of AI-driven applications.

What it solves

AISVS provides a structured, community-driven catalogue of testable security requirements for AI-enabled systems. It addresses the lack of technical, verifiable controls to secure AI applications throughout their entire lifecycle—from data collection and training to deployment and retirement—preventing them from being mere governance guidelines without actionable technical steps.

How it works

The standard organizes security requirements into 12 chapters covering areas such as training data integrity, input validation, supply chain security, and agentic orchestration. Each requirement is assigned one of three verification levels:

  • Level 1: Essential baseline controls for all AI systems.
  • Level 2: Standard controls for systems handling sensitive data or making consequential decisions.
  • Level 3: Advanced controls for high-assurance, safety-critical environments.

Users can apply these requirements as a security checklist during design, integrate them into CI/CD pipelines during development, or use them as a framework for penetration testing and audits.

Who it’s for

It is designed for developers, architects, security engineers, and auditors who need to verify the security of AI applications.

Highlights

  • Verifiable and Testable: Every requirement is designed to be implementable and verifiable, moving beyond high-level governance.
  • Comprehensive Lifecycle Coverage: Covers everything from training data to vector database security and Model Context Protocol (MCP) security.
  • Detailed Research Wiki: Includes a wiki that maps requirements to specific threats, CVEs, and concrete audit steps.
  • L3 Assurance: Provides a high-assurance path for critical infrastructure and regulated industries.

Related

  • Project
  • Project
  • Project
  • Dispatch
  • Project