Resources

Documentation, standards alignment, and project information.

Documentation

The framework specification and its Markdown reference live in the GitHub repository.

Framework Specification (PDF)

Complete technical reference — all 21 sub-metrics, five-level rubrics, test methods, ORP/ACI, and the Finbot validation. Also available as editable Word (.docx) and per-section Markdown.

View PDF on GitHub →

Gap Analysis

The twelve-gap structural analysis with 2025–2026 evidence and the AITBM-to-framework coverage mapping.

Read on the site →

AIDEFEND → AITBM Mapping

Translates AIDEFEND defensive techniques into measurable evidence for AITBM sub-metric scoring.

View on GitHub →

Per-section Markdown reference

The full specification split into readable Markdown sections — executive summary, architecture, scoring, the worked example, and references.

View on GitHub →

Standards alignment

AITBM aligns to, maps against, or explicitly addresses gaps in the standards and frameworks security teams already rely on.

OWASP Top 10 for LLMs

Severity quantification

OWASP Top 10 for Agentic Apps

Agentic threat coverage

OWASP AISVS

Control-verification input (pending)

OWASP AIVSS (v0.8)

Predecessor scoring system — structural gaps addressed

MITRE ATLAS

Threat taxonomy alignment

NIST AI RMF

Risk-management alignment

NIST Cyber AI Profile (IR 8596)

Cyber-AI intersection

ISO 42001 / 42005

Governance & impact assessment

EU AI Act

High-risk classification mapping

AIUC-1

Certification & insurance complement

AIDEFEND

Defensive-control evidence

MITRE D3FEND

Defensive taxonomy

CVSS

Prior art — why it is insufficient for AI

MCP

Primary agentic deployment class

About the project

AITBM is a community-driven, volunteer effort built for OWASP practitioners, AI security assessors, ML engineers, and compliance teams. It carries no commercial licensing and no paid-tooling dependencies, and is designed to be usable by assessors without an ML research background — every rubric is operationally concrete.

Led from the OWASP Taiwan Chapter, AITBM is developed in the open and its documentation is licensed under CC BY 4.0.

Get involved

  • Pilot an AITBM assessment on an agentic deployment and compare ERS to your existing scores.
  • Validate inter-assessor consistency on a shared system.
  • Open an issue or pull request with feedback and case studies.
Contribute on GitHub