The AI Learning Hub Journal

The Frameworks: OWASP, ATLAS, SAIF

Three AI security frameworks, three different jobsOWASP Top 10 for LLM AppsAPPLICATION-LEVEL CHECKLISTPrompt injectiondirect, and indirect via contentExcessive agencytoo many tools, too few limitsSupply chain riskmodels, plugins, training dataSensitive data exposureleaks through output and logsREACH FOR IT WHENreviewing a build before it shipsMITRE ATLASADVERSARY TACTICS MATRIXTactics × techniques gridthe AI counterpart to ATT&CKDocumented case studiesobserved attacks, not theoryRecon → access → impacthow an attack actually unfoldsShared vocabularyred and blue teams both speak itREACH FOR IT WHENthreat-modelling a systemGoogle SAIFSECURE-BY-DESIGN FRAMEWORKExtends existing controlsreuse your security foundationsAutomate the defenceskeep pace with new attacksPlatform-level guardrailsone control set, many modelsRisk in business contextend-to-end, not model-onlyREACH FOR IT WHENdesigning the system up frontCOMPLEMENTARY LENSES, NOT COMPETING STANDARDSDESIGN with SAIFTHREAT-MODEL with ATLASREVIEW with OWASPthen repeatA checklist finds omissions, a matrix names the adversary, a design framework stops the problem being built in
Three lenses on the same programme — none of them replaces the other two

OWASP Top 10 for LLM Applications

The industry-standard vocabulary for LLM risk. The headline entries: prompt injection (LLM01 — always first), sensitive information disclosure, supply chain vulnerabilities, data and model poisoning, improper output handling, excessive agency (the agent-era entry: too much autonomy, too many permissions, too little oversight), system prompt leakage, and unbounded consumption. You do not need to memorize the list — you need to recognize that when a security-mature colleague says "LLM01" they mean prompt injection, and that "excessive agency" is the entry that maps to everything this course says about scoped tools and approval gates.

MITRE ATLAS

ATLAS is to AI attacks what ATT&CK is to conventional intrusions: a matrix of adversary tactics and techniques targeting AI systems, from reconnaissance of a target model through poisoning, evasion, and exfiltration. Its value: when leadership asks "is AI attack surface actually real or vendor FUD?", ATLAS is the neutral, non-vendor answer — real incidents, catalogued techniques, mapped case studies.

Google SAIF

The Secure AI Framework is Google's contribution: six elements covering secure-by-default infrastructure, detection and response extended to AI, defense automation, harmonized platform controls, adaptive mitigations, and contextual risk assessment. SAIF matters when evaluating any cloud AI platform because it lets you check whether a platform's security controls are instances of a published framework or ad hoc features. Pair SAIF for design guidance with ATLAS for threat enumeration and OWASP for application-level checklists.

Putting Frameworks to Work

Frameworks convert "trust us" into "audit us." Three moves: (1) Pick the framework your organisation will use to assess AI risk — if there is none, introducing one makes you the educator in the room. (2) Require vendors to map their controls to your framework of choice — this is how security review meetings get shorter. (3) Use the "excessive agency" and "supply chain" entries to open the agent governance conversation internally. The team that brings the framework sets the evaluation criteria.

Prefer slides, quizzes, and saved progress? Read this lesson in the library — free, no sign-up.