OWASP Compliance Dashboard
Monitor compliance with AI security frameworks and standards
--
Overall Compliance
Loading...
--
OWASP LLM Top 10
Loading...
--
OWASP Agentic AI Top 10
Loading...
--
Fully Compliant
--
Partially Compliant
--
Non-Compliant
--
Total Controls
LLM01
Compliant
Prompt Injection
Manipulating LLMs via crafted inputs to cause unintended actions or expose sensitive data.
Critical Severity
Implemented Controls
Input validation and sanitization
Prompt boundary enforcement
Output filtering and monitoring
LLM02
Compliant
Insecure Output Handling
Trusting LLM outputs without validation can lead to XSS, CSRF, or code execution.
High Severity
Implemented Controls
Output encoding and escaping
Content Security Policy enforcement
Safe rendering practices
LLM03
Partial
Training Data Poisoning
Tampering with training data to introduce vulnerabilities, biases, or backdoors.
High Severity
Implemented Controls
Data source verification
Anomaly detection in training (partial)
Provenance tracking (planned)
LLM04
Compliant
Model Denial of Service
Resource-heavy operations causing service degradation or high costs.
Medium Severity
Implemented Controls
Rate limiting and throttling
Input length restrictions
Cost monitoring and alerts
LLM05
Compliant
Supply Chain Vulnerabilities
Risks from third-party components, models, or data sources in the LLM pipeline.
High Severity
Implemented Controls
Vendor security assessment
Model integrity verification
Dependency scanning
LLM06
Compliant
Sensitive Information Disclosure
Unintentional exposure of PII, credentials, or proprietary data through LLM outputs.
Critical Severity
Implemented Controls
PII detection and redaction
Data classification enforcement
Output DLP scanning
LLM07
Compliant
Insecure Plugin Design
Vulnerabilities in LLM plugins or integrations leading to code execution or data access.
High Severity
Implemented Controls
Plugin sandboxing
Capability-based permissions
Input/output validation
LLM08
Compliant
Excessive Agency
Granting LLMs excessive permissions to perform damaging actions without oversight.
Critical Severity
Implemented Controls
Least privilege enforcement
Human-in-the-loop for critical actions
Action logging and audit trails
LLM09
Partial
Overreliance
Trusting LLM outputs without verification leading to misinformation or errors.
Medium Severity
Implemented Controls
Confidence scoring display
Fact-checking integration (partial)
User disclaimers and warnings
LLM10
Compliant
Model Theft
Unauthorized access to proprietary LLM models through direct access or extraction.
High Severity
Implemented Controls
Access control and authentication
Rate limiting on API access
Query pattern monitoring
Recent Compliance Activity
Today, 10:32 AM
Automated compliance scan completed - 92% overall score
Yesterday, 3:15 PM
LLM06 (Sensitive Information Disclosure) upgraded to Compliant
Feb 8, 2026
ASI06 control review scheduled - Multi-Agent Coordination
Feb 7, 2026
Kill switch implementation verified for ASI03 compliance
Feb 5, 2026
New fingerprinting controls deployed for agent verification