OWASP Agentic AI guidance
Excessive agency, tool misuse, identity and privilege abuse, memory risks, cascading failures and human-control boundaries.
Mappings help security, engineering and governance teams communicate. They show which guidance is relevant to a finding; they do not turn a proprietary assessment into certification.
Excessive agency, tool misuse, identity and privilege abuse, memory risks, cascading failures and human-control boundaries.
Prompt injection, sensitive information disclosure, insecure output handling, excessive agency and supply-chain exposure.
Govern, map, measure and manage organisational AI risk with explicit context, accountability and monitoring.
Secure development, provenance, dependency integrity, build evidence and model or package supply-chain controls.
A framework label is useful only when scope, evidence, severity and remediation are still visible.
Record the agent, environment, tools, data and exclusions.
Show whether it was declared, observed, reproduced or recorded at runtime.
Reference the control or risk category that helps the owner understand the expectation.
A mapping is not proof of compliance, certification or complete framework coverage.
AgentRiskLayer Security Assessment — assessed against AgentRiskLayer Control Profile vX.Y. This proprietary assessment is not an accredited certification or a guarantee that the system is risk-free.