
The AI Security Verification Standard (AISVS) focuses on providing developers, architects, and security professionals with a structured checklist to verify the security of AI-driven applications.
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
The Artificial Intelligence Security Verification Standard (AISVS) is a community-driven catalogue of testable security requirements for AI-enabled systems. It gives developers, architects, security engineers, and auditors a structured framework to design, build, test, and verify the security of AI applications throughout their lifecycle, from data collection and model training to deployment, monitoring, and retirement.
AISVS is modeled after the OWASP Application Security Verification Standard (ASVS) and follows the same philosophy: every requirement should be verifiable, testable, and implementable.
This project was founded by Jim Manico. Current project leadership includes Jim Manico, Otto Sulin, Rico Komenda, and Russ Memisyazici.
| Standard | Focus | AISVS relationship |
|---|---|---|
| OWASP ASVS | Web application security | AISVS extends ASVS concepts to AI-specific threats |
| OWASP Top 10 for LLMs | Awareness of top LLM risks | AISVS provides the detailed controls to mitigate those risks |
| OWASP Top 10 for Agentic Applications | Awareness of top agentic AI risks | AISVS provides the detailed controls to address agentic-specific threats |
| NIST AI RMF | AI risk governance | AISVS supplies the testable technical controls that AI RMF references |
| ISO/IEC 42001 | AI management systems | AISVS complements with implementation-level security verification |
The latest stable version is AISVS 1.0, which can be found:
| Format | Link |
|---|---|
| AISVS 1.0 PDF | |
| Markdown (source) | Browse online |
Each AISVS requirement is assigned a verification level (1, 2, or 3) indicating the depth of security assurance:
| Level | Description | When to use |
|---|---|---|
| 1 | Essential baseline controls that every AI system should implement. | All AI applications, including internal tools and low-risk systems. |
| 2 | Standard controls for systems handling sensitive data or making consequential decisions. | Production systems, customer-facing AI, systems processing personal data. |
| 3 | Advanced controls for high-assurance environments requiring defense against sophisticated attacks. | Critical infrastructure, safety-critical AI, high-value targets, regulated industries. |
Organizations should select a target level based on the risk profile of their AI system. Most production systems should aim for at least Level 2.
For every requirement in the standard, the Research Wiki provides implementation context beyond the requirement text:
| Column | What it tells you |
|---|---|
| Threat Mitigated | Specific attack techniques, CVEs, and real-world incidents the control defends against |
| Verification Approach | Concrete audit steps, tools, and evidence to collect |
| Gaps & Notes | Tool maturity ratings, open research questions, and implementation caveats |
The wiki tracks the in-progress 1.01 release and covers every requirement in it, with per-section threat landscape summaries, tooling recommendations, and references to current standards and research literature. The wiki for the released 1.0 standard is frozen under 1.0/research.