From Scattered Guidance to a Single Adoption Path
The OWASP AI Exchange is a free, community-maintained reference for AI security. The goal: replace scattered guidance with a step-by-step adoption guide for organizations deploying GenAI, whether building models from scratch or buying solutions. It feeds into ISO, NIST, MITRE, and the EU AI Act with regular cadence meetings at each body. The project also collaborates closely with the OWASP LLM Top 10, whose version 2 is due within months. Published under Creative Commons 1.0, any organization can use or integrate its content without attribution.
A Decentralized Expert Network
Over 50 contributors from across the globe participate in bi-weekly calls. Members include US military and government alumni like Dan Sorensen, who brings visibility into the NIPR GPT project and the US Joint AI Center; red team and ML architecture specialists like Susanna Cox; and practitioners like Niv Braun, who combines Unit 8200 training with AI startup experience. The diversity of views and geographies means European regulatory moves land in the same conversation as US DOD AI programs and industry attack patterns.
The Full AI Stack, Not Just the LLM Runtime
The exchange takes a broader scope than most AI security discussions. When practitioners talk AI security, they default to LLMs and runtime threats. The framework covers the full development lifecycle, including open-source dependencies, misconfigurations, and supply chain risks that start before deployment. It also covers classic machine learning and predictive AI, not just generative models. These are the technologies already in mass adoption at most organizations, and attackers exploit them using the same techniques they already know.
Where the Exchange Influences Policy and Standards
The exchange holds a formal seat in the NIST Artificial Intelligence Safety Institute Consortium. Susanna Cox leads the gap analysis for NIST’s adversarial AI taxonomy, comparing NIST’s coverage against the exchange’s framework to identify blind spots. A separate requirements group is contributing directly to EU AI Act implementation rules, specifying what organizations must actually do to prove compliance. Cox also submitted a risk threshold assignment paper she expects will influence how the EU AI Act classifies AI system risk.
The Knowledge Gap Between Data Teams and Security Teams
AI and data teams work in a different vocabulary from security teams. They use terms like ETL pipelines and model lifecycle stages that are unfamiliar to security practitioners. Security teams use terms like dependency confusion and open-source supply chain attacks that data teams haven’t encountered. Niv Braun noted that practitioners in the same conversation often don’t mean the same thing. Susanna Cox’s fix: teach people that AI systems are statistics machines, not magic. That framing makes gradient-based attacks legible, and the controls follow from there.
The Fears the Panel Wouldn’t Dismiss
Susanna Cox’s top fear: social platforms powered by AI are wide open to takeover for election manipulation, and there is no responsible disclosure channel. She couldn’t publish the full details in 2022 because the attack surface is too dangerous to document publicly. Dan Sorensen’s fear: the white-hat community isn’t sharing fast enough while adversaries use AI to generate perfect-English phishing at scale. Niv Braun and Aruneesh Salhotra named supply chain the most dangerous gap. Every AI component added to a product is a potential entry point.
Q&A
Do you see AI replacing security jobs in the foreseeable future? Every panelist said no: AI will act as a force multiplier and introduce new security challenges, but the human inference and cross-system reasoning required in security work is far from automatable. ▶ Watch (38:13)
Why do AI teams keep repeating the same security mistakes that software teams already made? Niv Braun attributed it to prioritization: data and AI departments were not a high-value target until GenAI brought them into focus, and now that AI committees are forming inside organizations, basic security hygiene is finally receiving attention in those teams. ▶ Watch (40:45)
Should organizations build dedicated AI security teams or upskill existing security staff? Dan Sorensen said it depends on organization size, as specialization suits large organizations but isn’t universally sustainable; Niv Braun added that even a dedicated AI security person should stay embedded in the application security team given how closely AI components interact with production microservices. ▶ Watch (48:38)
Notable Quotes
everyone called me crazy for a year Susanna Cox · ▶ Watch (10:43)
not magic they are statistics machines Susanna Cox · ▶ Watch (29:40)
dangerous because I know there’s no way Susanna Cox · ▶ Watch (32:17)
the fear of us not working together Dan Sorensen · ▶ Watch (34:16)
Key Takeaways
- The OWASP AI Exchange feeds directly into NIST adversarial AI taxonomy and EU AI Act requirements.
- Real AI attacks start in the development phase, through misconfigurations and supply chain exposure, not just at runtime.
- Security and data teams don’t share a common language yet, and that gap is leaving AI deployments exposed.
About the Speaker(s)
Chloé Messdaghi is a cybersecurity leader focused on AI security standards and policy. She is the founder and principal consultant of SustainCyber, a founding member of Disclosed, a board member of the Diana Initiative, and has worked on election security and DEI research in cybersecurity.
Susanna Cox began pen testing and breaking AI systems in 2010. She later became a data scientist, ML engineer, ML architect, and chief data officer. In 2022 she published the first ML SecOps architecture paper, “Securing IML Systems in the Age of Information Warfare,” and holds patents pending for a federated machine learning security system. Her current research focuses on safety-critical engineering for AI and risk threshold assignment for AI regulation.
Aruneesh Salhotra is a technologist and servant leader with expertise across cybersecurity, DevSecOps, AI, business continuity, audit, and sales. He works as a fractional CISO through his consulting firm and runs independent research groups on generative AI and quantum computing. He is committed to security education across universities, schools, and nonprofits.
Dan Sorensen is a cybersecurity leader with over 22 years of experience as a CISO and cybersecurity engineer in aerospace. A US Air Force and Air National Guard veteran, he has worked in offensive and defensive cyber security and specializes in risk management and AI-driven defense strategies. He is an editor on the CSFI Geneva Manual on Cyber Threat Intelligence and a contributing author on a book about the AI mindset in cybersecurity.
Niv Braun is the CEO of Noma Security, a startup providing security, governance, and compliance across the data and AI lifecycle. Before founding Noma Security, he served as a security manager in Unit 8200, the Israeli Defense Forces’ elite cyber intelligence unit, where he worked on both security and data infrastructure.