SANS Institute and the OWASP AI Exchange have announced a strategic collaboration to create a unified set of AI security controls. This partnership addresses a growing concern: while enterprises are rapidly adopting AI technologies, they often lack proper security measures to guard against sophisticated threats such as prompt injection, data leakage, and model theft.
Despite the pace of AI adoption, defenders have been left without actionable, standardized guidance. This initiative bridges that critical gap by offering practical, field-tested protections that can be implemented across various industries.
“This partnership is about clarity,” said Rob van der Veer, founder of the OWASP AI Exchange. “We already have the technical foundation. SANS helps us bring it into the field and make it real for defenders.”
Key Highlights of the Initiative:
- The controls will integrate OWASP’s two years of AI security research (spanning over 200 pages) with the SANS Critical AI Security Guidelines v1.1.
- Focus areas include six vital domains: access, data, deployment, inference, monitoring, and governance.
- Outputs will align with regulatory standards such as the EU AI Act and ISO/IEC 27090, through an official liaison process.
- All control sets will be released as open-source resources to encourage broad adoption.
- SANS will integrate the controls into its global training programs, enabling enterprises and government agencies to adopt them directly.
“At this point, defenders do not need another framework. They need something they can use immediately,” said Rob T. Lee, Chief of Research at SANS Institute. “This partnership gives them tested protections based on real threats.”
This initiative aims to unite technical creators and operational defenders through a common control set, helping reduce ambiguity and foster global alignment around AI security standards.
Get Involved in the AI Security Standards Movement
Contributors are invited to shape the next generation of AI security standards through the following platforms:
- Submit your ideas via GitHub: github.com/sans-community or owaspai.org/contribute
- Fork the SANS or OWASP AI Exchange repository, branch off, edit Markdown, and submit a Pull Request. Be sure to link back to OWASP AI Exchange content where applicable.
- Join the OWASP community on Slack: owasp.org/slack/invite and connect in the public #project-ai-community channel.
For more updates on AI, IoT, cybersecurity, and expert insights, explore ITech360hub.
