Executive Summary

The OWASP AI Vulnerability Scoring System (AIVSS) represents a groundbreaking collaborative effort to establish standardized risk measurement for autonomous AI systems. This framework addresses the critical security challenges posed by "agentic AI" — artificial intelligence that can act autonomously to achieve goals. The link to download this document is here

Key Innovation

AIVSS complements traditional vulnerability scoring systems like CVSS by adding specialized metrics for AI-specific risks, including autonomy levels, goal manipulation, and multi-agent system vulnerabilities.

Community Impact

Developed through global collaboration of 100+ experts from industry, academia, and government.

This initial release (v0.5) serves as a call to action for the broader community to contribute to shaping the future of AI security standards. The framework identifies ten core security risk categories specific to agentic AI systems, providing organizations with tools to assess, prioritize, and mitigate emerging AI threats.

Why AIVSS Matters

Traditional vulnerability scoring systems were designed for conventional software and struggle to address the unique characteristics of Agentic AI systems. AIVSS fills this critical gap by providing specialized metrics and assessment methodologies tailored to the complexities of agentic AI.

Community & Leadership

The development of the OWASP AI Vulnerability Scoring System framework represents a significant collaborative effort within the cybersecurity and artificial intelligence communities. This initiative has brought together a diverse group of experts and organizations whose dedication and collaborative spirit have been instrumental in shaping this project.

Leadership Team and Leader Author of the Document

Ken Huang

Project Co-Lead, LinkedIn Profile, AI Book Author

Michael Bargury

Project Co-Lead, LinkedIn Profile, Founder and CTO of Zenity, expert in low-code/no-code security.

Vineeth Sai Narajala

Project Co-Lead, Application Security professional at AWS, bringing cloud security expertise. LinkedIn Profile

Bhavya Gupta

Project Co-Lead, Information Security Officer at Stanford University, hosts "AI Insiders" platform. LinkedIn Profile

OWASP Project Collaborators

OWASP AI Exchange

Led by Rob van der Veer, View Leader Profile

Focuses on sharing knowledge and best practices related to AI security, ensuring practical applicability of the AIVSS framework.

OWASP LCNC Top 10

Led by Kayla Underkoffler, View Leader Profile

Addresses security implications when agentic AI systems are built or integrated using low-code/no-code tools.

Key Contributors & Reviewers

The creation of the OWASP AIVSS v0.5 document was a collective endeavor, significantly shaped by the insights and expertise of numerous reviewers and contributors. These individuals, representing a wide spectrum of the AI and cybersecurity fields, volunteered their time and knowledge to critique, refine, and enhance the framework.

100+ Total Contributors; 25+Organizations; 15 Countries; 10 Months Development

The establishment of the AIVSS project (aivss.owasp.org) was a collaborative effort by the following founding members, listed alphabetically by last name:

Understanding Agentic AI

Defining Agentic AI

Agentic AI refers to artificial intelligence systems endowed with a degree of autonomy, allowing them to perform tasks, make decisions, and interact with their environment with minimal human intervention. These agents can learn from experience, adapt to new situations, and even collaborate with other agents or humans.

Key Characteristics

  • Goal-oriented behavior - Pursues objectives autonomously

  • Perception capabilities - Understands and interprets environment

  • Decision-making logic - Makes choices based on context

  • Action execution - Takes initiative to achieve goals

  • Memory systems - Learns from past experiences

Core Security Risks in Agentic AI

The unique architecture and operational modes of agentic AI introduce a distinct set of security vulnerabilities that go beyond traditional software flaws. The OWASP AIVSS framework identifies ten core security risk categories that are particularly critical in this new landscape.

Agentic AI Tool Misuse

When an agent's ability to use external tools is exploited to perform harmful actions unintended by the system designer.

Agent Access Control Violation

When an agent is tricked or manipulated into exceeding its authorized permissions, gaining access to sensitive data.

Agent Cascading Failures

A domino effect where failure in one agent triggers chain reaction failures in interconnected systems.

Agent Orchestration Exploitation

Targeting communication and coordination between multiple agents to cause widespread disruption.

Agent Identity Impersonation

When an agent's identity is faked or manipulated to impersonate legitimate users or other trusted agents.

Agent Memory Manipulation

Poisoning or corrupting an agent's memory to alter its future decisions and behaviors.

Insecure Critical Systems Interaction

Risk of compromised agents causing physical damage or safety hazards through critical infrastructure interaction.

Agent Supply Chain Risk

Vulnerabilities introduced through compromised components, libraries, models, or third-party services.

Agent Untraceability

Inability to effectively monitor, audit, or trace agent actions, making forensic analysis difficult.

Agent Goal Manipulation

Hijacking an agent's core purpose by feeding it deceptive, malicious, or biased goals and instructions.

A Call to Action: Help Shape the Future of AI Security

This v0.5 release of the OWASP AIVSS is just the beginning. The project leaders and contributors are actively seeking feedback from the global AI and cybersecurity communities to refine and strengthen this framework. By working together, we can build a more secure future for a world increasingly powered by autonomous AI systems.

We encourage everyone to read the paper, explore the concepts, and contribute to this vital open-source initiative.