Threat Intelligence

OWASP Releases New Security Blueprint to Tackle Risks in AI Skills and Add-ons

Dark Reading · 22 Aug 2026
Key Takeaway Before adopting AI-powered tools or add-ons, check whether they follow recognised security standards like OWASP's guidance to avoid introducing hidden risks into your business systems.

The Open Worldwide Application Security Project (OWASP), a well-known authority on software security, has released an updated top 10 list of security risks tailored to the growing use of artificial intelligence tools in business software. The new guidance specifically targets the risks introduced by AI 'skills' or add-ons — the extra features and plug-ins that extend what AI systems can do.

A key part of this update is the introduction of a Universal Skill Format, a standard designed to bring more consistency and built-in security to how these AI add-ons are built and used. As AI tools become more common in everyday business software, inconsistent or poorly secured add-ons can create new entry points for cyberattacks, making this kind of standardisation an important step for safer AI adoption.

For small and medium businesses increasingly relying on AI-powered tools — from chatbots to automated workflows — this development is a reminder that AI features aren't automatically secure just because they come from a trusted platform. Understanding what add-ons your business tools use, and whether they follow recognised security standards, is becoming a necessary part of good cyber hygiene.

Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from Dark Reading. We link back to every original so you can read it yourself.