Summary: The Top 10 outgrew itself. The parent project now runs initiatives on agentic security, AI SBOM, threat intel and red teaming, plus a glossary and a solutions landscape.
Sources: raw/OWASP-Top-10-for-LLMs/introduction-genai-security-project.md, project-mission-and-charter.md, initiatives*.md, glossary.md, resources.md, ai-security-solutions-landscape.md, resource-*.md
Last updated: 2026-07-28
Mission
“A global, open-source initiative dedicated to identifying, mitigating, and documenting security and safety risks associated with generative AI technologies, including large language models (LLMs), agentic AI systems, and AI-driven applications” (source: raw/OWASP-Top-10-for-LLMs/llm-top-10.md).
The Top 10 “continues to be a core component of our work” but is now one deliverable among several.
Initiatives
Agentic Security Initiative — “Securing autonomous agents and multi-step AI workflows.” It “explores the emerging security implications of agentic systems, particularly those utilizing advanced frameworks (e.g., LangGraph, AutoGPT, CrewAI) and novel capabilities like Llama 3’s agentic features” (source: initiatives-agentic-security-initiative.md).
Named frameworks matter here — this is the only source in the vault that engages with specific agent frameworks rather than agents in the abstract.
AI SBOM Initiative — an AIBOM generator and bill-of-materials work for AI systems (source: initiatives-ai-sbom-initiative.md). Directly relevant to the supply-chain gap: an AI SBOM is the artefact that would make LLM03 tractable, and it is the natural companion to CMU’s cryptographic chain of custody proposal.
Other initiatives listed: AI Threat Intelligence, Secure AI Adoption, AI Red Teaming (source: initiatives.md).
Glossary
A ~2,200-word controlled vocabulary “to clarify the language used throughout the OWASP Top 10 for LLM and OWASP Gen AI Security Project,” with a symbol legend distinguishing 🔷 Standard (agreed through voting, with source) from ✅ Approved (voted, with source) (source: glossary.md).
Definitions are sourced to authorities rather than invented — NIST AI 100-2 for adversarial attacks, 15 U.S. Code § 9401 for “artificial intelligence,” CISA’s JCDC AI Playbook for “AI cybersecurity incident.”
That last one is useful and absent elsewhere in this vault:
AI Cybersecurity Incident: “An occurrence that actually or imminently jeopardizes, without lawful authority, the confidentiality, integrity, or availability of the AI system, any other system enabled and/or created by the AI system, or information stored on any of these systems.” (Source: CISA)
Compare the three other meanings of “AI incident response” catalogued in AI incident response — this is a fourth, and the most CIA-triad-shaped of them.
AI Security Solutions Landscape
At ~11,400 words, the largest single document in this ingest. A vendor/solution directory mapping the AI security tooling market, with a Q2 2026 edition specific to AI and agentic red teaming (source: ai-security-solutions-landscape.md, resources.md).
Treat as a market map, not a technical reference — it catalogues who sells what.
Other resources
- LLM Applications Cybersecurity and Governance Checklist — a practitioner checklist bridging to governance concerns; the natural companion to the governance collection.
- State of Agentic AI Security and Governance
- AIUC-1 crosswalk to an OWASP Top 10 for Agentic Applications — indicating a separate agentic top 10 is in progress. Worth tracking; the vault’s evidence says that is where the risk has moved.
Resource categories on the site: cheat sheets, whitepapers, tools, learning videos, solutions directory.
Why the project’s shape is itself a finding
The trajectory — from “Top 10 for LLM Applications” (2023) to “GenAI Security Project” with a dedicated agentic initiative and an agentic top 10 in progress (2026) — tracks precisely what ATLAS shows in its platform tags and what PITAX’s indirect techniques show in their targets.
Three independent communities restructured their work around agents over the same period. AI Act Article 15(5), fixed in law since 2024, did not.
Caveat on these sources
Unlike the Top 10 entries — canonical markdown from the project repository — the pages on this collection were converted from a WordPress/Elementor site whose markup is roughly 90% shared navigation. Boilerplate was stripped by diffing the common prefix across all fetched pages. Content is faithful but layout-derived structure (tables, cards) may be flattened. For anything load-bearing, check the live page.