{"id":26190,"date":"2026-09-21T15:14:33","date_gmt":"2026-09-21T23:14:33","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2026\/09\/21\/new-owasp-tool-structures-ai-threat-modeling\/"},"modified":"2026-09-21T15:14:33","modified_gmt":"2026-09-21T23:14:33","slug":"new-owasp-tool-structures-ai-threat-modeling","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2026\/09\/21\/new-owasp-tool-structures-ai-threat-modeling\/","title":{"rendered":"New OWASP tool structures AI threat modeling"},"content":{"rendered":"<div class=\"rich-text_richText__UyrDZ\" data-anchor-headings=\"true\" data-component=\"rich-text\" data-reader-view=\"false\">\n<div class=\"payload-richtext\">\n<p>Organizations looking for a faster and more structured way to threat model their AI systems now have access to an open-source resource designed to help identify security risks before they become exploitable vulnerabilities.\u00a0<\/p>\n<p>The OWASP Foundation\u2019s <a href=\"https:\/\/notebooklm.google.com\/notebook\/e77101a5-b3a6-4c13-a348-7980c6d4adfe\/preview?pli=1\"><span style=\"text-decoration:underline\">Threat Advisor<\/span><\/a> is an AI-powered assistant that guides users through the threat modeling process by first asking them to describe their AI system and then conducting an interactive interview to identify relevant threats, assess risk, and recommend mitigations.\u00a0<\/p>\n<p>The recommendations draw on more than 300 pages of OWASP AI security guidance based on frameworks and standards such as <a href=\"https:\/\/www.linkedin.com\/company\/mosaicstandards\/about\/\"><span style=\"text-decoration:underline\">MOSAIC<\/span><\/a>. The free tool, which runs on Google&#8217;s NotebookLM, is the latest evolution of the OWASP AI Exchange&#8217;\u2019s efforts to make AI threat modeling more accessible.\u00a0<\/p>\n<p>The new assistant comes as many organizations are struggling to understand and contain new AI-specific risks and vulnerabilities such as prompt injection, supply chain compromise, excessive model privileges, and insecure agent deployments.<\/p>\n<p>Here\u2019s how Threat Adviser works \u2014 and how it can work for you.<\/p>\n<p><strong>[ See Webinar: <\/strong><a href=\"https:\/\/www.reversinglabs.com\/webinar\/forrester-agentic-development-security\"><strong>Securing Agentic Development with Forrester<\/strong><\/a><strong> ]<\/strong><\/p>\n<h2 id=\"building-on-owasps-ai-security-guidance\"><strong>Building on OWASP\u2019s AI security guidance<\/strong><\/h2>\n<p>OWASP\u2019s goal is for Threat Advisor to help organizations \u2014 especially those with limited resources or AI security expertise \u2014 to identify, evaluate, and prioritize those risks in the context of their own environment. They can avoid manually navigating hundreds of pages of documentation because the tool translates OWASP\u2019s guidance into a workflow they can use to help identify the threats most relevant to their specific AI deployment.\u00a0<\/p>\n<p>Rob van der Veer, founder of the OWASP AI Exchange, extolled the tool in a recent <a href=\"https:\/\/www.linkedin.com\/posts\/robvanderveer_today-owasp-ai-exchange-is-democratizing-activity-7474717441655386112-2BTQ\/?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAABVlr8B7bgYb2ey8pSyMQGzOLMElT9GA7w\"><span style=\"text-decoration:underline\">post on LinkedIn<\/span><\/a>.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cIf you are building or deploying AI, use this to get a high level threat model. It is the fastest way to understand your exposure \u2014 and where to focus next.\u201d<\/em><br \/><em>\u2014<\/em><a href=\"https:\/\/www.linkedin.com\/in\/robvanderveer?trk=feed-detail_main-feed-card_feed-actor-name\"><span style=\"text-decoration:underline\">Rob van der Veer<\/span><\/a><\/p>\n<h2 id=\"a-useful-guide-to-starting-ai-threat-modeling\"><strong>A useful guide to starting AI threat modeling<\/strong><\/h2>\n<p>Security experts view Threat Advisor as a useful starting point for AI threat modeling, particularly for organizations lacking dedicated security teams. The tool effectively surfaces many critical AI-specific categories, but the quality of its output will depend heavily on input accuracy and organizational context.<\/p>\n<p>Seemant Sehgal, founder and CEO of BreachLock, said an automated interview can surface relevant controls and map to known threat patterns.\u00a0<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cThe value of a tool like this depends entirely on what the organization brings to it. But it can only reason about what it\u2019s told, and most organizations struggle to articulate their own system boundaries, data flows, and trust assumptions clearly enough to get precise output.\u201d<\/em><br \/><em>\u2014<\/em><a href=\"https:\/\/www.linkedin.com\/in\/s-sehgal?trk=universal-search-cluster\"><span style=\"text-decoration:underline\">Seemant Sehgal<\/span><\/a><\/p>\n<p>The organizations that likely will benefit most from Threat Advisor, Sehgal added, are those that have practitioners who can validate the output, not those hoping the tool will do the thinking for them.<\/p>\n<p>Experts note that Threat Advisor can fill an important gap by helping organizations begin AI security conversations earlier in the development lifecycle. Jacob Krell, senior director of secure AI solutions and cybersecurity at Suzu Labs, noted that <a href=\"https:\/\/owaspai.org\/\"><span style=\"text-decoration:underline\">OWASP AI Exchange<\/span><\/a> has more than 300 pages of threat and control guidance that feeds into ISO and EU AI Act frameworks, but most teams deploying AI have never touched any of it.\u00a0<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cThreat Advisor turns that into a guided conversation you can run in a single sitting. For startups and mid-market companies shipping models without a security function, that\u2019s a real upgrade from \u2018we\u2019ll deal with it later.\u2019\u201d<\/em><br \/><em>\u2014<\/em>Jacob Krell<\/p>\n<p>Larger organizations that have AppSec programs will move through Threat Advisor faster, but even those teams tend to have blind spots in AI-specific threat coverage that the tool can help uncover.<\/p>\n<h2 id=\"why-context-matters\"><strong>Why context matters<\/strong><\/h2>\n<p>There are some caveats. Organizations using the tool should not confuse its automated guidance with a complete threat model. While Threat Advisor can help identify AI-specific risks, teams still need to evaluate those risks within the broader context of their application\u2019s architecture, business objectives, data flows, and existing security controls, said Jeff Williams, founder of OWASP and founder and CTO of Contrast Security.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cIt\u2019s a very interesting effort from the volunteers at OWASP, who have been doing a fantastic job at driving AI security forward.\u201d<\/em><br \/><em>\u2014<\/em><a href=\"https:\/\/www.linkedin.com\/in\/planetlevel?trk=universal-search-cluster\">Jeff Williams<\/a><\/p>\n<p>Williams said Threat Advisor is an early prototype and cautioned that effective threat modeling requires looking beyond AI-specific risks. \u201cThe most serious risks aren\u2019t AI-related,\u201d he said, noting that longstanding application security issues such as authentication weaknesses, access control failures, and injection flaws remain just as relevant.<\/p>\n<p>Williams also questioned whether an AI assistant can fully capture the architectural and operational context needed to produce a comprehensive threat model. \u201cIt\u2019s really all about context,\u201d he said, adding that organizations often lack a complete understanding of their own technology stack, data flows, trust boundaries, and threat environment.\u00a0<\/p>\n<p>That makes it difficult for any single person to answer Threat Advisor\u2019s questions with the level of detail required for precise results. Williams\u2019 advice: Give the AI assistant direct access to the organization\u2019s code repository and technical documentation to help answer the tool\u2019s questions more accurately. He also urges giving great feedback to the Threat Advisor team. \u201cHelp make it better,\u201d he said.<\/p>\n<h2 id=\"an-assistant-not-the-decision-maker\"><strong>An assistant, not the decision maker<\/strong><\/h2>\n<p>While Threat Advisor can help organizations assess their AI-related exposure, experts caution against treating its recommendations as definitive or prescriptive. The tool can help identify what threats apply, but humans still must prioritize risks based on business context, architecture, and actual operational environment.\u00a0<\/p>\n<p>For example, said Joshua Marpet, senior product security consultant at Finite State, while AI can efficiently examine logs, behavioral analytics, and other security telemetry in isolation, humans are still better at connecting those findings into a broader understanding of attacker activity.\u00a0 Since LLM-based assessments are inherently influenced by how users describe their systems, it\u2019s a good idea to run an analysis multiple times with different prompts to help validate and refine the results, he said.\u00a0<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cBe careful believing it 100%. Not that it\u2019s wrong. Just ask the question several ways.\u201d<\/em><br \/><em>\u2014<\/em><a href=\"https:\/\/www.linkedin.com\/in\/joshuaviktor\"><span style=\"text-decoration:underline\">Joshua Marpet<\/span><\/a><\/p>\n<p>Keel added that because Threat Advisor produces its results as a NotebookLM chat conversation and not as structured data, the recommendations cannot be easily imported into enterprise governance, risk, and compliance tools. Someone has to manually read the output, extract the findings, and enter them into the organization\u2019s risk management system.\u00a0<\/p>\n<p>That could lead to valid findings getting shelved because rewriting them as risk register entries feels like doing the work twice, he said. He said organizations need to keep that in mind and treat Threat Advisor appropriately.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cRun it before your architecture decisions harden. Treat the output as a starting point, then bring the threat list to your engineering team and pressure-test it against how your system actually runs in production. Do not let a NotebookLM conversation become your compliance artifact.\u201d<\/em><br \/><em>\u2014<\/em>Jacob Krell<\/p>\n<h2 id=\"appsec-strategy-transformationis-critical\" style=\"text-align:left\">AppSec strategy transformation\u00a0is critical<\/h2>\n<p style=\"text-align:left\">While Threat Advisor is a welcome addition to the security arsenal, more needs to be done. Specifically, teams need to modernize there application security (AppSec) approach for the AI era, Doug Levin, a board member at ReversingLabs, wrote recently reality-checking\u00a0<a href=\"https:\/\/www.reversinglabs.com\/blog\/how-mythos-changes-the-appsec-calculus\"><span style=\"text-decoration:underline\">Mythos\u2019 effect on AppSec<\/span><\/a>.\u00a0\u201cDon\u2019t get distracted by the headlines. Mythos is a milestone, not a destination. Organizations that understand that will come out ahead,&#8221; he wrote.<\/p>\n<p style=\"text-align:left;padding-inline-start:40px\"><em>&#8220;Yes, adversaries are getting an upgrade with AI. But the defensive answer is architectural, not transactional. Smart CISOs and organizations won\u2019t feel compelled to buy the flashiest, [most] cutting-edge AI security product \u2014 whether that\u2019s Mythos or the competitors that are already popping up.\u201d<\/em><br \/>\u2014<a href=\"https:\/\/www.linkedin.com\/in\/bduck1\/\"><span style=\"text-decoration:underline\">Doug Levin<\/span><\/a><\/p>\n<p style=\"text-align:left\">Levin wrote that with the next-generation AI, a serious AppSec program isn\u2019t a scanner stack. Instead, it\u2019s a multi-vector reasoning system built on five layers, he advised.<\/p>\n<p style=\"text-align:left\">Here are his five recommended layers:<\/p>\n<ul class=\"list-bullet\">\n<li class=\"\" style=\"text-align:left\" value=\"1\"><strong>Discovery:<\/strong>\u00a0Use supply chain threat intelligence on open-source packages, and integrate AI-assisted vulnerability research into CI\/CD pipelines so that defenders find issues before code ships.<\/li>\n<li class=\"\" style=\"text-align:left\" value=\"2\"><strong>Analysis:<\/strong>\u00a0Employ static analysis, SBOM tracking, and threat intelligence enrichment to give discovery context. Include a final build check on the binary. As Levin noted, SolarWinds, 3CX, and CodeCov were all build-pipeline compromises that source-code analysis missed.<\/li>\n<li class=\"\" style=\"text-align:left\" value=\"3\"><strong>Remediation:<\/strong>\u00a0Accelerate patching with AI, but include human review, since autonomous patching harbors the same hallucination risk as autonomous discovery.<\/li>\n<li class=\"\" style=\"text-align:left\" value=\"4\"><strong>Runtime:<\/strong>\u00a0Upgrade to detection and response tooling that assumes that one-day and even one-hour exploits are the norm and that can reason about code context at runtime.<\/li>\n<li class=\"\" style=\"text-align:left\" value=\"5\"><strong>Context:<\/strong>\u00a0Stitch identity, asset ownership, and blast-radius data across the stack, so response is accurate at speed.<\/li>\n<\/ul>\n<p style=\"text-align:left\"><em>Learn\u00a0<\/em><a href=\"https:\/\/www.reversinglabs.com\/blog\/why-rl-built-spectra-assure-community\"><em>why RL created Spectra Assure Community<\/em><\/a><em>. And\u00a0<\/em><a href=\"https:\/\/secure.software\/user\/signup?__hstc=60854195.09b88d157f9d43142772cad20253e99d.1783549571086.1783954443442.1783977546942.11&amp;__hssc=60854195.19.1783977546942&amp;__hsfp=8e1679cf18bde5534b91d07b1553c9bf\"><em>sign up for free\u00a0<\/em><\/a><em>to start building more secure software today.<\/em><\/p>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Organizations looking for a faster and more structured way to threat model their AI systems now have access to an open-source resource designed to help identify security risks before they become exploitable vulnerabilities.The OWASP Foundation\u2019sThreat Advisoris an AI-powered assistant that guides users through the threat modeling process by first asking them to describe their AI system and then conducting an interactive interview to identify relevant threats, assess risk, and recommend mitigatio<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[32775],"tags":[],"class_list":["post-26190","post","type-post","status-publish","format-standard","hentry","category-reversinglabs"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26190","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=26190"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26190\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=26190"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=26190"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=26190"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}