OWASP GenAI Security Project — Data Security Initiative
OWASP GenAI Data Security Risks and Mitigations 2026
Catalog of data-security risks across the GenAI lifecycle (DSGAI01–DSGAI21) with mitigations, authored by the Data Security Initiative of the OWASP GenAI Security Project.
14 mapped controls
- directive
AI-CTRL-001
AI System Inventory and Classification
Maintain a complete, current, and classified inventory of all AI systems in development, deployment, and decommissioning to enable risk-based governance.
GovernanceISO 42001 NIST AI RMF EU AI Act OWASP DSGAI +3v1.0.0 Reviewed 2026-05-01 - preventive
AI-CTRL-002
Training Data Provenance and Lineage
Establish and maintain documented provenance and lineage for all training, fine-tuning, and evaluation data used by AI systems, including legal basis, licensing, sensitivity classification, and transformations applied.
Data GovernanceISO 42001 NIST AI RMF EU AI Act OWASP LLM Top 10 +5v1.0.0 Reviewed 2026-05-01 - detective
AI-CTRL-003
Adversarial Robustness Testing for LLM Systems
Validate that production-bound LLM and agentic AI systems have been tested against direct prompt injection, indirect prompt injection, jailbreak, refusal evasion, and (where applicable) multi-modal adversarial inputs, with documented findings, remediation, and re-test cycles.
Security & Adversarial RobustnessISO 42001 NIST AI RMF EU AI Act OWASP LLM Top 10 +6v1.0.0 Reviewed 2026-05-01 - preventive
AI-CTRL-004
Third-Party AI Vendor Due Diligence
Ensure that third-party AI products and AI-enabled services are subject to risk-based due diligence covering data handling, model provenance, security testing, incident response, compliance posture, and contractual safeguards before procurement and on an ongoing basis.
Third-Party AIISO 42001 NIST AI RMF EU AI Act OWASP DSGAI +4v1.0.0 Reviewed 2026-05-01 - directive
AI-CTRL-005
AI Risk Assessment and Impact Assessment
Ensure that each AI system is subject to a documented risk assessment and AI System Impact Assessment (AIIA) aligned with ISO/IEC 23894 and ISO/IEC 42005, completed prior to production deployment and refreshed on material change or annually.
AI Risk ManagementISO 42001 NIST AI RMF EU AI Act OWASP DSGAI +3v1.0.0 Reviewed 2026-05-01 - preventive
AI-CTRL-007
Output Filtering and Content Moderation
Apply layered output filtering and content moderation to LLM and generative AI systems to prevent disclosure of sensitive data, prohibited content, executable payloads, and policy-violating outputs.
Inference & OutputISO 42001 NIST AI RMF EU AI Act OWASP LLM Top 10 +6v1.0.0 Reviewed 2026-05-01 - detective
AI-CTRL-011
Bias Testing and Fairness Validation
Validate performance, fairness, and disparate-impact metrics for AI systems with protected-class implications, using methods appropriate to the system type and use case, with documented findings and remediation.
Bias & FairnessISO 42001 NIST AI RMF EU AI Act OWASP DSGAI +1v1.0.0 Reviewed 2026-05-01 - directive
AI-CTRL-012
AI System Documentation and Model Cards
Maintain current, accessible technical documentation (model cards, datasheets, system cards) for every production AI system, sufficient to enable risk-based use, regulatory review, and downstream consumer understanding.
Transparency & ExplainabilityISO 42001 NIST AI RMF EU AI Act OWASP DSGAI +1v1.0.0 Reviewed 2026-05-01 - preventive
AI-CTRL-013
Personal Data Minimization in Training and Inference
Ensure that personal data used in training, fine-tuning, evaluation, and inference is minimized to the data strictly necessary for the stated purpose, processed under a defensible lawful basis, and subject to the rights of affected individuals.
PrivacyISO 42001 NIST AI RMF EU AI Act OWASP LLM Top 10 +5v1.0.0 Reviewed 2026-05-01 - preventive
AI-CTRL-015
Data Retention and Deletion for AI Systems
Define and enforce retention and deletion of AI-related data (training datasets, fine-tuning data, embeddings, prompts, completions, model artifacts, logs) per a documented schedule aligned to legal, regulatory, and operational requirements.
Data GovernanceISO 42001 NIST AI RMF EU AI Act OWASP DSGAI +3v1.0.0 Reviewed 2026-05-01 - directive
AI-CTRL-016
AI Acceptable Use Policy and User Training
Maintain a published, enforceable AI Acceptable Use Policy and deliver role-appropriate AI literacy training to employees, contractors, and other authorized users.
GovernanceISO 42001 NIST AI RMF EU AI Act OWASP DSGAI +3v1.0.0 Reviewed 2026-05-01 - preventive
AI-CTRL-017
Pre-Production AI Evaluation Gates
Require explicit, documented evaluation against defined thresholds — covering performance, fairness, robustness, safety, and (where applicable) drift baselines — as a gate to production deployment for every AI system.
Model LifecycleISO 42001 NIST AI RMF EU AI Act OWASP DSGAI +2v1.0.0 Reviewed 2026-05-01 - corrective
AI-CTRL-018
AI System Decommissioning
Ensure that AI system decommissioning follows a documented procedure addressing dependent system continuity, data retention/deletion, model artifact handling, vendor termination assistance, documentation preservation, and stakeholder communication.
Model LifecycleISO 42001 NIST AI RMF EU AI Act OWASP DSGAI +3v1.0.0 Reviewed 2026-05-01 - detective
AI-CTRL-020
Shadow AI Detection
Detect, triage, and remediate use of unsanctioned AI services and unauthorized AI tooling by employees, contractors, and other authorized users, with documented response and metrics.
GovernanceISO 42001 NIST AI RMF EU AI Act OWASP DSGAI +4v1.0.0 Reviewed 2026-05-01