SECAI Core · phase 8 of 15

Open Web Application Security Project

A charity and community publishing a number of secure application development resources.

The Explain card

Plain English
OWASP is a charity and open community that publishes free resources for building secure applications, from testing guides to well-known risk lists.
Example
A team building an LLM-powered helpdesk uses the OWASP Top 10 for LLM Applications as a checklist. It prompts them to test for prompt injection, insecure output handling, sensitive information disclosure and excessive agency before release.
Why it matters
OWASP distils community experience into practical, vendor-neutral guidance. For defenders of AI systems, it is often the quickest way to turn "we should secure this" into a concrete list of things to check.
Hook
The community cheat sheet for what attackers try first.

Where it sits in the deck

Phase 8: Governance, Risk, and Compliance Frameworks

Individual controls need a governance envelope — introduce the risk and compliance structures, standards bodies, and regulations that frame AI accountability at scale.