Guidelines  ·  2026-09-04

OWASP GenAI Security Project formally publishes Agent Control Standard (ACS) and debuts GenAI Security Industry Framework Crosswalk

GuidelinesHigh impactGlobal
On September 1, 2026 (confirmed via dated resource pages on genai.owasp.org), the OWASP GenAI Security Project formally published the Agent Control Standard (ACS) as a downloadable open specification (GitHub: GenAI-Security-Project/agent-control-standard) and released the new GenAI Security Industry Framework Crosswalk, an open resource mapping OWASP GenAI guidance to NIST, MITRE ATLAS, CWE and other established risk/compliance frameworks. This was announced publicly via a September 2 PR Newswire release (also covering unrelated sponsor and membership-milestone news). ACS defines how agent platforms expose middleware hooks and how safety policies can be enforced through them, enabling declarative, portable, runtime-enforced controls across agent frameworks — a step beyond the risk-identification focus of OWASP's existing LLM/Agentic Top 10 lists. Note: this is distinct from and builds on the August 26 announcement that ACS would be 'absorbed' into OWASP's Agentic Security Initiative (already covered) — September 1 is the actual publication of the standard document, source repo, and the new crosswalk resource, which is new, more substantive content. The OWASP 2026 LLM Top 10 itself was published August 3-4, 2026 (outside this window) and is not re-reported here.
ACS is one of the first vendor-neutral, open specifications aimed specifically at runtime enforcement of agent behavior (what an agent can access, decide, and do) rather than static risk checklists. Combined with the Framework Crosswalk, it gives security teams and vendors a common enforcement substrate and a way to map GenAI controls into existing NIST/MITRE/CWE-based compliance programs, which will likely be referenced by agent-platform vendors seeking to demonstrate control maturity.
Security architects building or buying agent platforms should evaluate ACS's middleware-hook model against internal agent deployments; compliance/GRC teams should use the Framework Crosswalk to map existing NIST/MITRE ATLAS control obligations onto GenAI-specific guidance rather than starting a parallel program.
OWASP GenAI Security Project — Agent Control Standard (ACS) resource pagePR Newswire / OWASP releaseOWASP GenAI Security Project blog announcement
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →