SECAI Core · phase 8 of 15
Open Web Application Security Project
A charity and community publishing a number of secure application development resources.
The Explain card
- Plain English
- OWASP is a charity and open community that publishes free resources for building secure applications, from testing guides to well-known risk lists.
- Example
- A team building an LLM-powered helpdesk uses the OWASP Top 10 for LLM Applications as a checklist. It prompts them to test for prompt injection, insecure output handling, sensitive information disclosure and excessive agency before release.
- Why it matters
- OWASP distils community experience into practical, vendor-neutral guidance. For defenders of AI systems, it is often the quickest way to turn "we should secure this" into a concrete list of things to check.
- Hook
- The community cheat sheet for what attackers try first.
Where it sits in the deck
Phase 8: Governance, Risk, and Compliance Frameworks
Individual controls need a governance envelope — introduce the risk and compliance structures, standards bodies, and regulations that frame AI accountability at scale.