Council of AI — OWASP AI Exchange mapping
GSPC axes → OWASP AI Exchange
The OWASP AI Exchange (owaspai.org, CC0 1.0) organises AI security into 7 sections with 10 essential control subcategories. The 22 axis · 22 measured GSPC board measures behavioural and financial axes. This page maps each GSPC axis to the OWASP concern it addresses. The mapping is a CSOAI editorial act — not an OWASP endorsement. One axis may span multiple categories.
Coverage table
Each row is one OWASP category. Axes listed are measured on the GSPC board. Sources: OWASP AI Exchange v1.0 (Dec 2025), cited at owaspai.org.
Governance, Risk & Compliance
§1 General Controls
Art 5-safeguard measures EU AI Act Art 50 marking readiness; regulatory-framework measures statutory register membership.
Supply Chain Management
§1 General Controls
Provenance tracks model and data lineage; custody and attestation track financial supply chains.
Limit Unwanted Behaviour
§1 General Controls
Safety = adversarial robustness; care = harm-avoidance; jail = containment; affect = emotional safety.
Input Threats (Evasion, Prompt Injection, Extraction)
§2 Input Threats
Swarm measures coordinated multi-model attack surfaces; detector-interop measures adversarial detector resistance; cross-reality measures cross-domain transfer.
Development-Time Threats (Data Poisoning, Model Leaks)
§3 Development-Time
Provenance = data lineage; continuity = model versioning and reproducibility; openness = code and weight transparency.
Runtime Security (Model Leaks, Output Injection, Resource Exhaustion)
§4 Runtime Security
Machinery-conformity = runtime safety-critical compliance (Machinery Regulation); conformance = MCP/API protocol adherence; distribution-integrity = runtime financial distribution correctness.
AI Security Testing
§5 Testing
GSPC's measurement IS testing: frozen banks, deterministic grading, signed cards. Every measured axis carries per-item evidence a stranger can re-verify.
AI Privacy
§6 Privacy
Care measures data-handling safety; affect measures emotional/privacy boundaries; custody-disclosure measures financial data transparency.
Sensitive Data Minimisation
Essentials — Limit
Care includes data minimisation subtasks; reserve attestation measures disclosure granularity (never the reserves themselves).
Model Behaviour Constraints (Oversight, Transparency, Least Privilege)
Essentials — Limit
Art 5-safeguard = Art 50 transparency readiness; adoption/labour/humanoid axes measure real-world deployment constraints.
Axis → category index
Reverse lookup: for each GSPC axis, which OWASP categories it addresses.
Method note
This mapping places each GSPC axis against the OWASP AI Exchange section or essential subcategory whose threat model the axis most directly measures. An axis may appear in multiple categories when it addresses overlapping concerns (e.g. "safety" addresses both input threats and behaviour limiting). The OWASP AI Exchange is the authoritative source for AI security controls; GSPC axes are the measurement instruments. Coverage of a category means at least one GSPC axis measures something in that category's scope — it does not mean the category is exhaustively covered. We measure presence of published commitments, never their quality.
Source: OWASP AI Exchange, owaspai.org, CC0 1.0. CSOAI mapping as_of 2026-09-15. This is a CSOAI editorial act. OWASP does not endorse this mapping.