Documentation, standards alignment, and project information.
Use these guides to choose a benchmark, design an assessment, select evaluation methods, compare external frameworks, or find a relevant incident reference.
System-level safety, security, and evidence confidence.
A repeatable deployment assessment workflow.
Tests and evidence routes across 23 rubrics.
OWASP, MITRE, NIST, ISO, EU, CSA, and more.
64 complete public-evidence records by topic.
The framework specification and its Markdown reference live in the GitHub repository.
Complete technical reference — all 23 sub-metrics, five-level rubrics, test methods, ORP/ACI, and the Finbot validation. Also available as editable Word (.docx) and per-section Markdown.
View PDF on GitHub →The twelve-gap structural analysis with 2025–2026 evidence and the AITBM-to-framework coverage mapping.
Read on the site →Answer plain-language Yes/No questions about your AI system and receive an indicative ERS instantly — no account required, runs entirely in the browser.
Open calculator →Translates AIDEFEND defensive techniques into measurable evidence for AITBM sub-metric scoring.
View on GitHub →The full specification split into readable Markdown sections — executive summary, architecture, scoring, the worked example, and references.
View on GitHub →AITBM aligns to, maps against, or explicitly addresses gaps in the standards and frameworks security teams already rely on.
Severity quantification
Agentic threat coverage
Control-verification input (1.0)
Predecessor scoring system — structural gaps addressed
Threat taxonomy alignment
Risk-management alignment
Cyber-AI intersection
Governance & impact assessment
High-risk classification mapping
Certification & insurance complement
Defensive-control evidence
Defensive taxonomy
Prior art and complementary scope
Primary agentic deployment class
AITBM is a community-driven, volunteer effort built for OWASP practitioners, AI security assessors, ML engineers, and compliance teams. It carries no commercial licensing and no paid-tooling dependencies, and is designed to be usable by assessors without an ML research background — every rubric is operationally concrete.
Led from the OWASP Taiwan Chapter, AITBM is developed in the open and its documentation is licensed under the MIT License.