AI Governance Library

AIVSS Scoring System for OWASP Agentic AI Core Security Risks v0.8

The framework posits that agentic capabilities do not just add new risks; they fundamentally expand the "blast radius" of existing technical vulnerabilities.
AIVSS Scoring System for OWASP Agentic AI Core Security Risks v0.8

⚡ Quick Summary

The AIVSS Scoring System for OWASP Agentic AI Core Security Risks v0.8 introduces a quantitative vulnerability assessment framework designed specifically for autonomous, multi-agent AI ecosystems. Developed collaboratively by OWASP AIVSS, AIUC-1, OWASP AI Exchange, and OWASP Citizen Development Top 10, the report addresses the fundamental limitation of traditional scoring models like CVSS v4.0 when applied to autonomous systems: that agentic capabilities act as a "Force Multiplier" that drastically amplifies the blast radius of standard technical vulnerabilities. The framework establishes ten Core Agentic AI Security Risks and pairs them with a mathematical scoring equation that computes an Agentic Uplift (AARS) based on ten amplification factors, threat maturity, and mitigation strength, providing security teams with actionable metrics for prioritization and remediation.

🧩 What's Covered

The document is organized into two primary sections complemented by extensive reference architectures, taxonomies, and technical appendices:

  • Part 1: The 10 OWASP Agentic AI Core Security Risks: Detailed descriptions, key failure modes, prevention techniques, and real-world attack scenarios covering: (1) Agentic AI Tool Misuse, (2) Agent Access Control Violation, (3) Agent Cascading Failures, (4) Agent Orchestration and Multi-Agent Exploitation, (5) Agent Identity Impersonation, (6) Agent Memory and Context Manipulation, (7) Insecure Agent Critical Systems Interaction, (8) Agent Supply Chain and Dependency Risk, (9) Agent Untraceability, and (10) Agent Goal and Instruction Manipulation.
  • Part 2: The AIVSS-Agentic Mathematical Framework: Establishes the Risk Amplification Model where technical baseline severity (CVSS v4.0) is modified by ten discrete amplification factors evaluated on an ordinal scale (0.0, 0.5, 1.0): Autonomy, Tools, Language, Context, Non-Determinism, Opacity, Persistence, Identity, Multi-Agent, and Self-Modification.
  • Mathematical Formulation: Details the exact uplift equation AARS = (10 - CVSS_Base) * (Factor_Sum / 10) * ThM and the primary score formula AIVSS = (CVSS_Base + AARS) * Mitigation_Factor, incorporating default Threat Multipliers (0.97 for PoC) and a calibrated Mitigation Factor floor (0.67 for strong mitigations).
  • Governance & Lifecycle Implementation: Outlines governance structures including the AI Governance Board and AI Risk Classification Committee, along with role definitions spanning AI Security Leads, AI Reliability & Policy Engineers (AI RPE), and SecOps/GRC teams.
  • Standard Crosswalks & Schemas: Provides mappings to the CSA MAESTRO 7-layer reference architecture, OWASP Agentic AI Top 10 for 2026, NIST AI RMF (Govern, Map, Measure, Manage), and includes a full draft-07 JSON Schema for automated report generation.

💡 Why it matters?

In autonomous agent environments, traditional vulnerability scoring breaks down because minor technical flaws (e.g., a low-severity information disclosure or prompt injection) can trigger catastrophic downstream impacts when executed by agents with high autonomy, persistent memory, or tool execution privileges. AIVSS provides an empirical bridge between software vulnerability metrics (CVSS v4.0) and runtime AI governance, demonstrating mathematically why architectural remediation (constraining autonomy, scoping tools, isolating memory) is often more effective than traditional code patching.

❓ What's Missing

As a v0.8 release, several operational areas remain provisional. The mathematical mitigation factor floor of 0.67 is an initial reference anchor awaiting broader empirical validation from enterprise production deployments. Additionally, while the report provides a quantitative scoring model, integration with qualitative decision-tree approaches (such as Stakeholder-Specific Vulnerability Categorization / SSVC) is noted as an ongoing parallel effort that has not yet been fully integrated into the unified scoring pipeline.

👥 Best For

This report is essential reading for AI Security Engineers, CISOs, Product Security Architects, AI Red Teams, and GRC professionals responsible for deploying, assessing, or governing autonomous multi-agent systems and Model Context Protocol (MCP) toolchains.

📄 Source Details

  • Document Title: AIVSS Scoring System For OWASP Agentic AI Core Security Risks v0.8
  • Publishing Bodies: OWASP AIVSS, AIUC-1, OWASP AI Exchange, OWASP Citizen Development Top 10
  • Lead Authors: Ken Huang, Michael Bargury, Vineeth Sai Narajala, Bhavya Gupta, Tim Marple
  • Target Release Context: 2026 Agentic AI Deployments

📝 Thanks to

Curated and reviewed by Kuba Szarmach for the AI Governance Library (aigl.blog). Special recognition to the lead authors (Ken Huang, Michael Bargury, Vineeth Sai Narajala, Bhavya Gupta, Tim Marple), AIUC partner Emil Bender Lassen, project leaders Rob van der Veer and Kayla Underkoffler, and the OWASP AIVSS Distinguished Review Board.

About the author
Jakub Szarmach

AI Governance Library

Curated Library of AI Governance Resources

AI Governance Library

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to AI Governance Library.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.