Framework · OWASP · v1.0, June 2026 · free
OWASP AISVS
AI Security Verification Standard: 12 chapters, about 191 pass/fail requirements over three assurance levels, with agentic (C9) and MCP (C10) chapters.
Developer and verifier audience.
Source: owasp.org↗
Against the five tests
The map is scored for a specific reader: a firm of roughly 20 to 500 people, no CISO and no compliance department, using agents it bought and agents it built, looking for a named document it can check itself against.
| Test | The question | Score |
|---|---|---|
| Agent-scoped | Covers agents, tools, MCP and autonomy, not AI in general. | ✔ |
| Adopter-facing | Usable by a firm deploying agents, not only building them. | ✘ |
| Checklist-shaped | Enumerable requirements you can pass or fail. | ✔ |
| Right-sized | Digestible without dedicated security staff. | ✘ |
| Recognised | A name a client, auditor or insurer would accept. | ✔ |
✔ yes · ◐ partly · ✘ no · scores are this site’s reading of the document
The sixth test: risk across many agents
The five tests above ask whether a firm can use each document. A sixth question sits underneath them, and none of the five brings it out: does any of these documents address risk that appears across many agents at once, rather than inside one?
◐A swarm-level kill-switch and inter-agent controls, within one orchestrator's own fleet.
✔ addresses it · ◐ names it, within one system · ✘ does not