The OWASP AI Vulnerability Scoring System enables organizations to quantify how agentic capabilities amplify security risks, producing numerical scores (0-10) that combine technical vulnerability severity with agent-specific factors like autonomy, tool access, and memory persistence.
AIUC-1 integrates the OWASP AIVSS, which is a technical contributor to AIUC-1. Certification against AIUC-1:
- Covers all agent risks identified in AIVSS
- Enables organizations to mitigate risks quantified in OWASP AIVSS
- Incorporates AIVSS agent risk amplification factors in standard requirements
OWASP AIVSS crosswalks by risk
Last updated February 26, 2026.