

Practical AI Security Assessments Using OWASP AISVS
How do you actually verify that an AI system is secure? In this workshop, the OWASP AI Security Verification Standard (AISVS) project leader Jim Manico will walk through practical assessment scenarios using the OWASP AISVS.
We'll work through real requirements from chapters on prompt injection defense, agentic action security, RAG/vector database hardening, and output safety controls, showing what "verify that" looks like in practice against running systems.
Participants will leave with a working understanding of how to scope an AI security assessment, select appropriate verification levels, and apply AISVS requirements to LLM-based applications, autonomous agents, and MCP-connected tool ecosystems.
Bring a laptop if you want to follow along.