
Executive Summary
The OWASP AI Vulnerability Scoring System (AIVSS) represents a groundbreaking collaborative effort to establish standardized risk measurement for autonomous AI systems. This framework addresses the critical security challenges posed by "agentic AI" — artificial intelligence that can act autonomously to achieve goals. The link to download this document is here
Key Innovation
AIVSS complements traditional vulnerability scoring systems like CVSS by adding specialized metrics for AI-specific risks, including autonomy levels, goal manipulation, and multi-agent system vulnerabilities.
Community Impact
Developed through global collaboration of 100+ experts from industry, academia, and government.
This initial release (v0.5) serves as a call to action for the broader community to contribute to shaping the future of AI security standards. The framework identifies ten core security risk categories specific to agentic AI systems, providing organizations with tools to assess, prioritize, and mitigate emerging AI threats.
Why AIVSS Matters
Traditional vulnerability scoring systems were designed for conventional software and struggle to address the unique characteristics of Agentic AI systems. AIVSS fills this critical gap by providing specialized metrics and assessment methodologies tailored to the complexities of agentic AI.
Community & Leadership
The development of the OWASP AI Vulnerability Scoring System framework represents a significant collaborative effort within the cybersecurity and artificial intelligence communities. This initiative has brought together a diverse group of experts and organizations whose dedication and collaborative spirit have been instrumental in shaping this project.
Ken Huang
Project Co-Lead, LinkedIn Profile, AI Book Author
Michael Bargury
Project Co-Lead, LinkedIn Profile, Founder and CTO of Zenity, expert in low-code/no-code security.
Vineeth Sai Narajala
Project Co-Lead, Application Security professional at AWS, bringing cloud security expertise. LinkedIn Profile
Bhavya Gupta
Project Co-Lead, Information Security Officer at Stanford University, hosts "AI Insiders" platform. LinkedIn Profile
OWASP Project Collaborators
OWASP AI Exchange
Led by Rob van der Veer, View Leader Profile
Focuses on sharing knowledge and best practices related to AI security, ensuring practical applicability of the AIVSS framework.
OWASP LCNC Top 10
Led by Kayla Underkoffler, View Leader Profile
Addresses security implications when agentic AI systems are built or integrated using low-code/no-code tools.
Key Contributors & Reviewers
The creation of the OWASP AIVSS v0.5 document was a collective endeavor, significantly shaped by the insights and expertise of numerous reviewers and contributors. These individuals, representing a wide spectrum of the AI and cybersecurity fields, volunteered their time and knowledge to critique, refine, and enhance the framework.
Mahesh Lambe, MIT, Stanford
Joshua Beck, SAS Institute
Mohsin Khan, SAP Concur
Michael Morgenstern, DayBlink Consulting
Jacob Rideout, HiddenLayer
Nate Lee, Trustmind.com
Praveen Gupta, Uber Technologies Inc
Rajivarnan R, SECNORA
Manish Kumar Yadav, SAP
Vaibhav Agrawal, Google
Srihari, The Home Depot
Viswanath S Chirravuri, ThalesGroup
Dor Sarig, Pillar Security
Lewis Peach, Google Public Sector
Debjyoti Mukherjee, RBC
Angus Chen, Qerberos
Sri Sushmitha Janapareddy, American Express
Hammad Atta, Roshan Consulting and Qorvex Consulting
Om Narayan, AWS
Edward Lee, JPMorgan Chase & Co.
Diana Kelley, SecurityCurve
Omar A. Turner, Microsoft
Mehmet Ali Özer, safenlp.org
Gauri Sharma, Georgia Tech
Colin Shea-Blymyer, Center for Security and Emerging Technology
Vidhi Kulkarni, Georgia Tech
Kashif Memon, Amazon
Manish Bhatt, OWASP/Amazon Kuiper Security
Keren Katz, Apex Security (Acquired by Tenable)
Jian Wang, McKinsey & Company
Charles Iheagwara, AstraZeneca
Madhu Dama, SAP Labs
Ads Dawson, Dreadnode
Anthony Glynn, Capital One
Thi Minh Phuong Nguyen, Secure GenAI
Rico Komenda, adesso SE
Ying-Jung Chen, Independent Consulting
Mayank Sharma, Deutsche Bank
Barak Sternberg, Formerly Wild Pointer
Semih Gelişli, CTO
Paola Garcia Cardenas, NYU, OWASP/OpenCRE
Nicholas Carlini, Anthropic
Talesh Seeparsan, Bit79
Tyson Powell, Juume AI
Chase Pettet, Life360
Guillaume Bonnet, Akamai Technologies
Kayla Underkoffler, Zenity
Tal Shapira, Reco
Mark Breitenbach, Dropbox
David Ormrod, Cygence
Michael Hamilton, KPMG
Cecil Su, BDO
Daniela Muhaj, Georgetown University & AI 2030
David Webb, CISA
Marissa Dotter, MITRE Corp.
Eugene Neelou, OWASP
Alaeddin Selçuk Gürel, Bahçeşehir University
Nir Paz, Tango Secure
Matthew R. Versaggi, AI PIF - GSA/CMS
Aamiruddin Syed, AGCO Corp
Sam Watts, Lakera
Steve Giguere, Lakera
David Haber, Lakera
Dave, Owasp AI Exchange
George DeCesare, Cybersecurity Risk Executive and Board Member
100+ Total Contributors; 25+Organizations; 15 Countries; 10 Months Development
The establishment of the AIVSS project (aivss.owasp.org) was a collaborative effort by the following founding members, listed alphabetically by last name:
Sunil Agrawal - Chief Information Security Officer, Glean
David Ames - Partner, PwC
Michael Bargury - Founder and CTO, Zenity
Joshua Beck - Application Security Architect, SAS
Manish Bhatt - Security Researcher, Amazon Kuiper Security
Mark Breitenbach - Security Engineer, Dropbox
Anat Bremler-Barr - Professor of Computer Science, Tel Aviv University
Siah Burke - HIPAA Security Officer, Siah.ai
David Campbell - AI Security, Scale AI
Ying-Jung Chen - AI safety researcher, PhD, Georgia Institute of Technology
Anton Chuvakin - Security Solution Strategy, Google
Jason Clinton - CISO, Anthropic
Adam Dawson - Staff AI Security Researcher, Dreadnode
Ron F. Del Rosario - VP-Head of AI Security, SAP
Walker Lee Dimon - AI Security Researcher, MITRE
Marissa Dotter - AI Security Researcher, MITRE
Leon Derczynski - Principal Research Scientist, NVIDIA
Dan Goldberg - ISO Market Lead, Omnicom
David Haber - CEO, Lakera
Idan Habler - Staff AI/ML Security Researcher, Intuit
Jason Haddix - Founder, Arcanum Information Security
Keith Hoodlet - Director of AI/ML & AppSec, Trail of Bits
Ken Huang - AIVSS Project Lead, OWASP
Chris Hughes - CEO, Aquia
Charles Iheagwara - AI/ML Security Leader, AstraZeneca
Krystal Jackson - Researcher, Center for Long-Term Cybersecurity, UC Berkeley
Sushmitha Janapareddy - Director - Security Integrations, American Express
Rob Joyce - Former Cybersecurity Director of NSA, Advisor to PwC, PwC
Diana Kelley - CISO, Protect AI
Prashant Kulkarni - Lead AI Security Research Engineer, Google Cloud
Mahesh Lambe - Founder, MIT, Unify Dynamics
Edward Lee - Vice President, Lead AI Security, JP Morgan
Nate Lee - CEO, Cloudsec.ai
Vishwas Manral - CEO, Precize.ai
Daniela Muhaj - Executive-in-Residence for Research & Development, AI 2030
Om Narayan - AI Security Researcher, AWS
Vineeth Sai Narajala - Application Security, AWS
Advait Patel - Senior Site Reliability Engineer (DevSecOps + Cloud + AIOps), Broadcom, IEEE
Alex Polyakov - CEO, adversa.ai
Ramesh Raskar - Professor & Director, MIT Media Lab
Tal Shapira - Co-Founder & CTO, Reco AI
Akram Sheriff - Senior AI/ML Software Engineering Leader, Cisco
Samantha Siau - Security and Compliance, Anthropic
Kevin Simmonds - Partner on AI Offensive Security, PWC
Martin Stanley - NIST AI RMF Lead, Independent
Omar A. Turner - General Manager of Security, Microsoft
Apostol Vassilev - AI Research Team Supervisor, NIST
Matthew Versaggi - AI Fellow, White House Presidential Innovation Fellow
David Webb - Agency Cybersecurity Officer, Cybersecurity and Infrastructure Security Agency
Dennis Xu - Research VP, AI, Gartner
Xiaochen Zhang - Executive Director and Chief Responsible AI Officer, AI 2030
Understanding Agentic AI
Defining Agentic AI
Agentic AI refers to artificial intelligence systems endowed with a degree of autonomy, allowing them to perform tasks, make decisions, and interact with their environment with minimal human intervention. These agents can learn from experience, adapt to new situations, and even collaborate with other agents or humans.
Key Characteristics
Goal-oriented behavior - Pursues objectives autonomously
Perception capabilities - Understands and interprets environment
Decision-making logic - Makes choices based on context
Action execution - Takes initiative to achieve goals
Memory systems - Learns from past experiences

Core Security Risks in Agentic AI
The unique architecture and operational modes of agentic AI introduce a distinct set of security vulnerabilities that go beyond traditional software flaws. The OWASP AIVSS framework identifies ten core security risk categories that are particularly critical in this new landscape.
Agentic AI Tool Misuse
When an agent's ability to use external tools is exploited to perform harmful actions unintended by the system designer.
Agent Access Control Violation
When an agent is tricked or manipulated into exceeding its authorized permissions, gaining access to sensitive data.
Agent Cascading Failures
A domino effect where failure in one agent triggers chain reaction failures in interconnected systems.
Agent Orchestration Exploitation
Targeting communication and coordination between multiple agents to cause widespread disruption.
Agent Identity Impersonation
When an agent's identity is faked or manipulated to impersonate legitimate users or other trusted agents.
Agent Memory Manipulation
Poisoning or corrupting an agent's memory to alter its future decisions and behaviors.
Insecure Critical Systems Interaction
Risk of compromised agents causing physical damage or safety hazards through critical infrastructure interaction.
Agent Supply Chain Risk
Vulnerabilities introduced through compromised components, libraries, models, or third-party services.
Agent Untraceability
Inability to effectively monitor, audit, or trace agent actions, making forensic analysis difficult.
Agent Goal Manipulation
Hijacking an agent's core purpose by feeding it deceptive, malicious, or biased goals and instructions.
A Call to Action: Help Shape the Future of AI Security
This v0.5 release of the OWASP AIVSS is just the beginning. The project leaders and contributors are actively seeking feedback from the global AI and cybersecurity communities to refine and strengthen this framework. By working together, we can build a more secure future for a world increasingly powered by autonomous AI systems.
We encourage everyone to read the paper, explore the concepts, and contribute to this vital open-source initiative.