OWASP AIVSS Project Announces the Release of v0.8 Scoring System for Agentic AI Security Risks in Co-Publication with AIUC-1 and Leading OWASP Projects

OWASP AIVSS Project Announces the Release of v0.8 Scoring System for Agentic AI Security Risks in Co-Publication with AIUC-1 and Leading OWASP Projects

Agentic AI
Agentic AI Mar 19, 2026

Key Takeaways

  • v0.8 integrates 1,900 community comments
  • Updated quantitative model improves risk amplification scoring
  • Crosswalk maps AIVSS to AIUC-1 standards
  • Aligns with NIST AI RMF and CSA MAESTRO
  • SSVC decision-tree adds qualitative prioritization

Summary

The OWASP Agentic AI Vulnerability Scoring System (AIVSS) released version 0.8 on March 19, 2026, incorporating over 1,900 public comments and new mappings to AIUC‑1, NIST AI RMF, and CSA MAESTRO. The update adds a refined quantitative model, revised core risks, enhanced usability, and an empirical appendix of expert survey data. A strategic co‑publication delivers a crosswalk linking AIVSS to AIUC‑1, positioning the framework for cyber‑insurance and compliance use cases. Parallel work launches an SSVC decision‑tree to guide qualitative risk prioritization ahead of the v1.0 target later this year.

Pulse Analysis

The release of AIVSS v0.8 marks a pivotal step in standardizing how enterprises evaluate the security posture of autonomous AI agents. By integrating a massive feedback loop of 1,900 practitioner comments, the framework now reflects real‑world threat landscapes, offering a more precise quantitative model that captures risk amplification unique to agentic systems. This evolution aligns the scoring methodology with leading industry standards such as NIST’s AI Risk Management Framework, CSA MAESTRO, and the emerging AIUC‑1 specification, creating a bridge between technical assessment and regulatory compliance.

Beyond the numbers, the new crosswalk between AIVSS and AIUC‑1 provides a practical pathway for cyber‑insurance underwriting and risk transfer. Insurers can now reference a shared scoring language to price policies, while organizations gain a clear compliance checklist that dovetails with existing governance programs. The inclusion of an empirical appendix, featuring expert survey rankings, adds credibility and data‑driven insight, helping security teams prioritize remediation efforts based on documented risk severity.

Complementing the quantitative upgrades, the project’s simultaneous rollout of an SSVC decision‑tree introduces a qualitative layer for stakeholder‑specific prioritization. This hybrid approach acknowledges that raw scores alone cannot dictate remediation; contextual business impact and stakeholder risk appetite must shape action plans. As the community prepares for the public review period starting April 16, 2026, and the roadmap toward a full v1.0 release, AIVSS is poised to become the de‑facto benchmark for agentic AI security, influencing product design, compliance audits, and strategic risk management across the AI ecosystem.

OWASP AIVSS Project Announces the Release of v0.8 Scoring System for Agentic AI Security Risks in Co-Publication with AIUC-1 and Leading OWASP Projects

Comments

Want to join the conversation?