Guidelines  ·  2026-10-03

OWASP Top 10 Neocloud and AI Data Center Security Risks (FORGE framework)

GuidelinesMedium impactGlobal
An OWASP-hosted framework (github.com/owasp/owasp-top-10-neocloud-and-ai-data-center-security-risks; companion site forge-framework.io) cataloguing the Top 10 security risks in neocloud/GPU-cloud and AI data center infrastructure. It defines FORGE domains — Fleet integrity, Operations & management planes, Resource isolation, Grid (networking/facilities), Evidence & exposure management — with a severity-ordered risk matrix scoring likelihood, impact and detection difficulty, led by risks such as hardware/firmware integrity compromise and unsafe multi-tenant isolation. Reviewers include security leaders from Dell, Google, IBM, Roblox, Nebius, Lava, Zenity and Aqua Security. The exact original publication date could not be firmly established on OWASP's own domain; a syndication mirror carries a 2026-09-30 datestamp, which falls inside the reporting window but is treated as indicative rather than authoritative.
This extends OWASP's AI-security coverage below the model/application layer to the shared accelerator/GPU infrastructure that trains and serves AI. It gives neocloud providers and customers a shared vocabulary for procurement, hardening and maturity assessment of AI compute, complementing the OWASP LLM Top 10, MITRE ATLAS and NIST AI RMF, in an area (multi-tenant GPU clusters, model theft, firmware/supply-chain integrity) where no comparable OWASP control catalogue previously existed.
Neocloud/GPU-cloud providers and AI-infrastructure customers should map their AI data-center environments to the FORGE risk matrix as a procurement and hardening checklist; practitioners should bookmark it for adoption once official OWASP publication is confirmed.
OWASP — owasp-top-10-neocloud-and-ai-data-center-security-risks (GitHub)FORGE framework site
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →