Overview

OWASP AI Exchange is described as 'the world's AI security guide': an openly licensed, 300+ page framework of practical threats and controls for securing AI and machine learning systems. It functions as a global think tank and as the key open-source input — the 'connective tissue' — feeding international AI security and privacy standards.

It is released under CC0 1.0 — a public domain dedication that lets anyone freely copy, adapt and reuse the content without attribution (attribution is appreciated but not required), which is precisely what makes it usable as raw material inside formal standards.

  • Founded 22 Oct 2022 by Rob van der Veer (originally the 'AI security and privacy guide').
  • Awarded OWASP Flagship project status in March 2025.
  • Led by 70+ carefully selected experts: researchers, practitioners, vendors and data scientists.

Threats & Controls Structure

The framework maps threats across the AI lifecycle and pairs each with controls, organized into deep-dive sections: general (governance) controls, threats through use (input threats), development-time threats, runtime conventional security threats, plus AI security testing and AI privacy.

  • Development-time threats: training-data poisoning, model poisoning, supply-chain compromise, and development-time data leaks in the engineering environment.
  • Runtime / use-time threats: evasion (adversarial input), prompt injection (direct & indirect), model theft/extraction, sensitive-data disclosure & membership inference, and AI resource exhaustion (model DoS).
  • Runtime conventional security: traditional IT attacks adapted to AI assets, including injection via model output.
  • General governance controls: AIPROGRAM, SECPROGRAM, DEVPROGRAM, SECDEVPROGRAM, CHECKCOMPLIANCE, SECEDUCATE, plus limiting unwanted model behaviour and data minimisation.
  • Development-time controls: dev-environment security, data segregation/protection, federated learning and supply-chain management.
  • Runtime app controls: model & I/O integrity, model confidentiality, access control, rate limiting, input validation and output filtering.
  • Data-science defenses: training-data hardening (poison resistance), adversarial/evasion robustness, ensembles and quality control.

Feeding Global Standards

Because it is CC0, AI Exchange acts as a standards feeder: its content is contributed directly into formal AI security and privacy standards, with founder Rob van der Veer serving as liaison officer and co-editor across the relevant bodies.

  • ISO/IEC 27090 (AI security guidance): ~70 pages contributed; expected 2026.
  • ISO/IEC 27091 (AI privacy): in development, OWASP working-group participation.
  • EU AI Act / CEN-CENELEC prEN 18282 (AI security): substantial OWASP contribution; van der Veer is co-editor; public enquiry early 2026.
  • OWASP holds an official liaison partnership with CEN/CENELEC, approved unanimously by EU member states.
  • Aligns with NIST, ENISA and links security standards globally via OpenCRE.

AI Exchange is complementary to the OWASP GenAI Security Project (home of the LLM Top 10): the two cross-reference each other, with AI Exchange providing the broad, standards-grade depth across all AI types (including predictive ML) while GenAI focuses on generative AI and agentic threats.

How to Use It

Teams use AI Exchange as a single reference to build an AI security program, run threat modelling, select controls and prepare for regulation. The interactive Navigator diagram maps the relationships between threats, controls, risks and control types so users can drill from a risk to concrete mitigations.

  • Map your AI use case to development-time vs runtime threats, then pick the matching controls.
  • Use it as a regulatory bridge — its content underpins forthcoming EU AI Act and ISO standards.
  • Combine with the OWASP GenAI/LLM Top 10 for generative-AI-specific awareness.

History

  • 2022 (Oct): Initiated by Rob van der Veer as the 'AI security and privacy guide'.
  • 2023: Rebranded as 'AI Exchange' to emphasise global collaboration and standards alignment.
  • Mar 2025: Awarded OWASP Flagship project status (alongside the GenAI Security Project).
  • 2025–2026: Grows rapidly as the open-source bridge into ISO/IEC and EU AI Act standards.
The world's AI security guide — connecting practitioners, researchers, industry and policymakers to bring clarity to AI security.

Official Resources