GenAI Crosswalk
GenAI Crosswalk is the flagship dataset and tool of the OWASP GenAI Security Project. It is the most comprehensive mapping of Gen AI and Agentic security risks to industry frameworks: 51 entries across the OWASP LLM Top 10, the OWASP Top 10 for Agentic Applications, DSGAI (Data Security for GenAI) and the OWASP Agentic Skills Top 10, mapped to 25 industry frameworks with 3,497 individual control mappings.
Review state. Every mapping in this project is unreviewed until a named reviewer signs it. 2 of the 25 mapped frameworks — CoSAI and the EU AI Act Code of Practice — currently carry candidate rows only: the control ids are accurate to the published framework, but the pairing to a risk is a proposal awaiting subject-matter review, not an assertion. They are counted as mapped because a mapping file exists; they are not counted as verified, because nothing here is.
OWASP Top 10 for Agentic AI — Risks & Mitigations
See the full OWASP Top 10 for Agentic AI risks and mitigations: Agent Goal Hijack, Tool Misuse & Exploitation, Identity & Privilege Abuse, Agentic Supply Chain Vulnerabilities, Unexpected Code Execution, Memory & Context Poisoning, Insecure Inter-Agent Communication, Cascading Agent Failures, Human-Agent Trust Exploitation, and Rogue Agents.
OWASP LLM Top 10 — Risks & Mitigations
See the full OWASP LLM Top 10 risks and mitigations: Prompt Injection, Sensitive Information Disclosure, Supply Chain Vulnerabilities, Data and Model Poisoning, Improper Output Handling, Excessive Agency, Hidden Context Exposure, Vector and Embedding Weaknesses, Misinformation, and Unbounded Consumption.
AI Security Standards Crosswalk
See the full crosswalk of 25 industry AI security standards, including NIST AI RMF, ISO/IEC 42001, EU AI Act, FedRAMP, DORA, MITRE ATLAS, OWASP ASVS, OWASP SAMM, PCI DSS, and SOC 2.
This project is free and open-source (CC BY-SA 4.0), maintained by the OWASP GenAI Security Project. Enable JavaScript to use the interactive explorer, coverage scorer, and gap analysis tools.