OWASP AISVS: The AI Security Standard the Industry Has Been Missing

On 24 June 2026, OWASP released version 1.0 of the Artificial Intelligence Security Verification Standard, AISVS for short, and for those of us who test web applications (and increasingly the AI features bolted onto them) this is the standard we have been waiting for.

Until recently, testing an AI-enabled feature meant improvising. Testers could borrow adjacent controls from the OWASP Application Security Verification Standard (ASVS), lean on the OWASP Top 10 for LLM Applications for a sense of the risk landscape, and draw techniques and methodology from the AI Testing Guide that OWASP published in late 2025. But the rest needed to be filled with judgement built from experience, because there was no purpose-built standard to test to.

AISVS now helps close that particular gap. It is a community-driven, testable set of requirements that have been purpose-built for AI systems. It is organised into twelve control families that span the full AI lifecycle from training data through deployment, monitoring, and eventual retirement.

Structurally, AISVS behaves exactly like ASVS, which makes it straightforward for users already familiar with that standard to pick up. Requirements are written as testable “Verify that” statements, organised into three ascending assurance levels, and those levels are explicitly aligned to ASVS levels, so an AI application being tested at Level 2 is expected to have its underlying non-AI application tested to ASVS Level 2 as well.

AISVS is also deliberately narrow. It does not attempt to repeat what ASVS, SCVS, or ISO/IEC 42001 already cover; it only adds the layer that is genuinely specific to AI.

A few examples give an idea of the ground AISVS covers:

  • There is a dedicated control family for prompt injection and content screening, treating any input capable of steering model behaviour as untrusted by default.
  • There is a substantial section on orchestration and agentic security, covering execution budgets, approval gates for high-impact or irreversible actions, and the specific security requirements for the Model Context Protocol that increasingly sits behind agent-to-tool integrations (which warrants an entire chapter of its own).
  • And there is a full chapter on model supply chain security, requiring signed and integrity-verified model artefacts, dataset provenance tracking, and an AI-specific bill of materials, the same discipline that SBOMs brought to traditional software dependencies, now applied to weights, adapters, and training data.

This is precisely the sweet spot of what we specialise in at phew. Our approach has always been to test wherever possible against a defined, internationally recognised standard, rather than an internal checklist or the OWASP Top 10 alone, because this provides a structured methodology and a higher, more valuable assurance level – and therefore something concrete to hand your board, your auditors, and your customers.

AISVS gives us that same foundation for the AI-enabled features now showing up in an increasing share of the applications we test, rather than leaving AI-specific risk to be assessed on an ad hoc basis bolted onto a conventional web application engagement.

If your organisation has shipped, or is about to ship, an AI-enabled application or feature and you need assurance that goes beyond “we ran a scan”, we would welcome the conversation. Get in touch.

Scroll to Top