What happened
An OWASP-hosted framework (github.com/owasp/owasp-top-10-neocloud-and-ai-data-center-security-risks; companion site forge-framework.io) cataloguing the Top 10 security risks in neocloud/GPU-cloud and AI data center infrastructure. It defines FORGE domains — Fleet integrity, Operations & management planes, Resource isolation, Grid (networking/facilities), Evidence & exposure management — with a severity-ordered risk matrix scoring likelihood, impact and detection difficulty, led by risks such as hardware/firmware integrity compromise and unsafe multi-tenant isolation. Reviewers include security leaders from Dell, Google, IBM, Roblox, Nebius, Lava, Zenity and Aqua Security. The exact original publication date could not be firmly established on OWASP's own domain; a syndication mirror carries a 2026-09-30 datestamp, which falls inside the reporting window but is treated as indicative rather than authoritative.
Why it matters
This extends OWASP's AI-security coverage below the model/application layer to the shared accelerator/GPU infrastructure that trains and serves AI. It gives neocloud providers and customers a shared vocabulary for procurement, hardening and maturity assessment of AI compute, complementing the OWASP LLM Top 10, MITRE ATLAS and NIST AI RMF, in an area (multi-tenant GPU clusters, model theft, firmware/supply-chain integrity) where no comparable OWASP control catalogue previously existed.
Action needed
Neocloud/GPU-cloud providers and AI-infrastructure customers should map their AI data-center environments to the FORGE risk matrix as a procurement and hardening checklist; practitioners should bookmark it for adoption once official OWASP publication is confirmed.