Council of AI — OWASP AI Exchange mapping

GSPC axes → OWASP AI Exchange

The OWASP AI Exchange (owaspai.org, CC0 1.0) organises AI security into 7 sections with 10 essential control subcategories. The 22 axis · 22 measured GSPC board measures behavioural and financial axes. This page maps each GSPC axis to the OWASP concern it addresses. The mapping is a CSOAI editorial act — not an OWASP endorsement. One axis may span multiple categories.

Coverage table

Each row is one OWASP category. Axes listed are measured on the GSPC board. Sources: OWASP AI Exchange v1.0 (Dec 2025), cited at owaspai.org.

1.1

Governance, Risk & Compliance

§1 General Controls

OWASP ↗
GovernanceArt 5-SafeguardRegulatory

Art 5-safeguard measures EU AI Act Art 50 marking readiness; regulatory-framework measures statutory register membership.

1.2

Supply Chain Management

§1 General Controls

OWASP ↗
ProvenanceCustodyReserve Attestation

Provenance tracks model and data lineage; custody and attestation track financial supply chains.

1.3

Limit Unwanted Behaviour

§1 General Controls

OWASP ↗
SafetyCareJailAffect

Safety = adversarial robustness; care = harm-avoidance; jail = containment; affect = emotional safety.

2

Input Threats (Evasion, Prompt Injection, Extraction)

§2 Input Threats

OWASP ↗
SafetySwarmDetectorCross-Reality

Swarm measures coordinated multi-model attack surfaces; detector-interop measures adversarial detector resistance; cross-reality measures cross-domain transfer.

3

Development-Time Threats (Data Poisoning, Model Leaks)

§3 Development-Time

OWASP ↗
ProvenanceContinuityOpenness

Provenance = data lineage; continuity = model versioning and reproducibility; openness = code and weight transparency.

4

Runtime Security (Model Leaks, Output Injection, Resource Exhaustion)

§4 Runtime Security

OWASP ↗
MachineryConformanceDistribution

Machinery-conformity = runtime safety-critical compliance (Machinery Regulation); conformance = MCP/API protocol adherence; distribution-integrity = runtime financial distribution correctness.

5

AI Security Testing

§5 Testing

OWASP ↗
GovernanceSafetyCareJailSwarmDetector

GSPC's measurement IS testing: frozen banks, deterministic grading, signed cards. Every measured axis carries per-item evidence a stranger can re-verify.

6

AI Privacy

§6 Privacy

OWASP ↗
CareAffectCustody

Care measures data-handling safety; affect measures emotional/privacy boundaries; custody-disclosure measures financial data transparency.

C1

Sensitive Data Minimisation

Essentials — Limit

OWASP ↗
CareReserve Attestation

Care includes data minimisation subtasks; reserve attestation measures disclosure granularity (never the reserves themselves).

C2

Model Behaviour Constraints (Oversight, Transparency, Least Privilege)

Essentials — Limit

OWASP ↗
GovernanceArt 5-SafeguardOpennessAI AdoptionLabourHumanoid Labour

Art 5-safeguard = Art 50 transparency readiness; adoption/labour/humanoid axes measure real-world deployment constraints.

Axis → category index

Reverse lookup: for each GSPC axis, which OWASP categories it addresses.

Affect→ 1.3, 6
AI Adoption→ C2
Art 5-Safeguard→ 1.1, C2
Care→ 1.3, 5, 6, C1
Conformance→ 4
Continuity→ 3
Cross-Reality→ 2
Custody→ 1.2, 6
Detector→ 2, 5
Distribution→ 4
Governance→ 1.1, 5, C2
Humanoid Labour→ C2
Jail→ 1.3, 5
Labour→ C2
Machinery→ 4
Openness→ 3, C2
Provenance→ 1.2, 3
Regulatory→ 1.1
Reserve Attestation→ 1.2, C1
Safety→ 1.3, 2, 5
Swarm→ 2, 5

Method note

This mapping places each GSPC axis against the OWASP AI Exchange section or essential subcategory whose threat model the axis most directly measures. An axis may appear in multiple categories when it addresses overlapping concerns (e.g. "safety" addresses both input threats and behaviour limiting). The OWASP AI Exchange is the authoritative source for AI security controls; GSPC axes are the measurement instruments. Coverage of a category means at least one GSPC axis measures something in that category's scope — it does not mean the category is exhaustively covered. We measure presence of published commitments, never their quality.

Source: OWASP AI Exchange, owaspai.org, CC0 1.0. CSOAI mapping as_of 2026-09-15. This is a CSOAI editorial act. OWASP does not endorse this mapping.