Supported Compliance Frameworks
Asenion AI Red Teaming maps every attack plugin to one or more industry frameworks, so your test results line up with the controls those frameworks define — not just raw security data. When you run a test suite, the results dashboard shows pass/fail rates per framework control, and you can export framework-aligned reports.

OWASP LLM Top 10 (2025)
The OWASP LLM Top 10 is the most widely adopted framework for identifying and mitigating common security risks in large language model applications.
| Control | Name | Attack Plugins |
|---|---|---|
| LLM01 | Prompt Injection | indirect-prompt-injection, ascii-smuggling, cca, hijacking, system-prompt-override, special-token-injection |
| LLM02 | Sensitive Information Disclosure | cross-session-leak, prompt-extraction, data-exfil, rag-document-exfiltration, pii:* |
| LLM03 | Supply Chain | shell-injection, sql-injection, ssrf, mcp, tool-discovery, coding-agent:* |
| LLM04 | Data and Model Poisoning | agentic:memory-poisoning, rag-poisoning, divergent-repetition, harmbench, beavertails |
| LLM05 | Improper Output Handling | hallucination, overreliance, unverifiable-claims, imitation, politics, religion |
| LLM06 | Excessive Agency | excessive-agency, goal-misalignment, tool-discovery, mcp, coding-agent:* |
| LLM07 | System Prompt Leakage | prompt-extraction, system-prompt-override, debug-access, model-identification |
| LLM08 | Vector and Embedding Weaknesses | rag-poisoning, rag-source-attribution, cross-session-leak, data-exfil |
| LLM09 | Misinformation | hallucination, harmful:misinformation-disinformation, politics, unverifiable-claims |
| LLM10 | Unbounded Consumption | reasoning-dos, divergent-repetition, excessive-agency |
OWASP Top 10 for Agentic Applications (v1)
Covers risks specific to autonomous, tool-using, and multi-agent AI systems.
| Control | Name | Attack Plugins |
|---|---|---|
| A01 | Autonomous Decision Making Failure | excessive-agency, goal-misalignment, hijacking |
| A02 | Tool Misuse | tool-discovery, mcp, shell-injection, sql-injection, ssrf |
| A03 | Memory and Context Poisoning | agentic:memory-poisoning, cross-session-leak, rag-poisoning |
| A04 | Insufficient Guardrails | system-prompt-override, debug-access, rbac, prompt-extraction |
| A05 | Identity and Access Control | bola, bfla, rbac, telecom:account-takeover |
| A06 | Prompt Hijacking | indirect-prompt-injection, ascii-smuggling, cca, hijacking, system-prompt-override |
| A07 | Secret and Data Exfiltration | data-exfil, rag-document-exfiltration, cross-session-leak, pii:*, coding-agent:* |
| A08 | Sandbox and Boundary Escape | coding-agent:* |
| A09 | Unsafe Automation and Persistence | coding-agent:* |
| A10 | Insufficient Logging and Monitoring | debug-access, divergent-repetition, agentic:memory-poisoning |
NIST AI Risk Management Framework (AI RMF 1.0)
The NIST AI RMF provides a structured approach for organizations to govern, map, measure, and manage AI risks.
| Function | Name | Attack Plugins |
|---|---|---|
| GOVERN | Governance | contracts, excessive-agency, politics, religion |
| MAP | Risk Identification | harmbench, beavertails, donotanswer, harmful:* |
| MEASURE-BIAS | Bias Measurement | imitation, donotanswer, bias:* |
| MEASURE-PRIVACY | Privacy Measurement | cross-session-leak, prompt-extraction, pii:* |
| MEASURE-ROBUSTNESS | Robustness Measurement | indirect-prompt-injection, hallucination, overreliance, reasoning-dos |
| MANAGE | Risk Management | debug-access, agentic:memory-poisoning, ssrf, mcp |
EU AI Act
The European Union AI Act establishes risk-tiered obligations for AI systems, with strict requirements for high-risk applications covering prohibited practices, transparency, human oversight, and accuracy.
| Article | Name | Attack Plugins |
|---|---|---|
| Art. 5 | Prohibited Practices | politics, religion, imitation, goal-misalignment, harmful:*, teen-safety:* |
| Art. 10 | Data and Governance | harmbench, beavertails, agentic:memory-poisoning, bias:* |
| Art. 13 | Transparency | prompt-extraction, system-prompt-override, hallucination, model-identification |
| Art. 14 | Human Oversight | excessive-agency, contracts, rbac |
| Art. 15 | Accuracy and Robustness | hallucination, overreliance, unverifiable-claims, reasoning-dos |
ISO/IEC 42001 (2023)
The international standard for AI Management Systems. Asenion AI Red Teaming maps tests to key controls in the standard’s risk assessment, operation, monitoring, and accountability domains.
| Control | Name | Attack Plugins |
|---|---|---|
| 6.1.2 | AI Risk Assessment | contracts, excessive-agency, overreliance, hallucination, harmful:* |
| 8.4 | AI System Operation | hallucination, unverifiable-claims, overreliance, reasoning-dos |
| 8.5 | AI System Impact | imitation, politics, religion, bias:* |
| 9.1 | Monitoring and Measurement | debug-access, divergent-repetition, agentic:memory-poisoning |
| 10.1 | Continual Improvement | cross-session-leak, prompt-extraction, system-prompt-override, pii:* |
| A.6.2 | Data Quality | harmbench, beavertails, agentic:memory-poisoning, rag-poisoning |
| A.9.3 | System Transparency | prompt-extraction, system-prompt-override, model-identification |
| A.10.3 | Accountability and Access Control | rbac, bfla, bola, debug-access |
GDPR
The General Data Protection Regulation. Asenion AI Red Teaming covers privacy, data minimization, security of processing, and data protection by design.
| Article | Name | Attack Plugins |
|---|---|---|
| Art. 5 | Principles Relating to Processing | cross-session-leak, data-exfil, prompt-extraction, pii:* |
| Art. 25 | Data Protection by Design | rbac, bfla, bola, debug-access |
| Art. 32 | Security of Processing | ssrf, sql-injection, shell-injection, cross-session-leak, coding-agent:* |
MITRE ATLAS
MITRE ATLAS (Adversarial Threat Landscape for Artificial-Intelligence Systems) catalogs adversarial tactics and techniques targeting AI systems.
| Technique | Name | Attack Plugins |
|---|---|---|
| AML.T0000 | Reconnaissance | tool-discovery, debug-access, model-identification |
| AML.T0051 | Prompt Injection | indirect-prompt-injection, ascii-smuggling, cca, hijacking, system-prompt-override |
| AML.T0044 | Memory Poisoning | agentic:memory-poisoning, rag-poisoning |
| AML.T0025 | Model Inversion and Exfiltration | prompt-extraction, cross-session-leak, data-exfil, rag-document-exfiltration, pii:* |
| AML.T0020 | Data Poisoning | harmbench, beavertails, divergent-repetition, agentic:memory-poisoning |
| AML.T0054 | Defense Evasion | pliny, ascii-smuggling, system-prompt-override, special-token-injection, coding-agent:* |
| AML.T0018 | Privilege Escalation | rbac, bfla, bola, excessive-agency, telecom:account-takeover |
MIT AI Ethics
Responsible AI principles aligned to fairness, transparency, privacy, safety, oversight, accountability, and robustness — derived from MIT’s AI Ethics framework.
| Principle | Name | Attack Plugins |
|---|---|---|
| FAIRNESS | Fairness and Non-Discrimination | imitation, donotanswer, bias:* |
| TRANSPARENCY | Transparency | prompt-extraction, system-prompt-override, hallucination, model-identification |
| PRIVACY | Privacy | cross-session-leak, data-exfil, prompt-extraction, pii:* |
| SAFETY | Safety | beavertails, harmbench, donotanswer, harmful:*, teen-safety:* |
| HUMAN_OVERSIGHT | Human Oversight | excessive-agency, contracts, rbac |
| ACCOUNTABILITY | Accountability | bola, bfla, rbac, debug-access |
| ROBUSTNESS | Robustness | indirect-prompt-injection, ascii-smuggling, divergent-repetition, reasoning-dos |
Additional Domain Frameworks
Some plugins are mapped to sector-specific regulations and standards:
| Framework | Sector | Relevant Plugins |
|---|---|---|
| Fair Housing Act | Real Estate | realestate:fair-housing-discrimination, realestate:steering |
| CPNI (FCC) | Telecommunications | telecom:cpni-disclosure |
| TCPA | Telecommunications | telecom:tcpa-violation |
| Youth Safety | Consumer / Teen Products | teen-safety:dangerous-content, teen-safety:dangerous-roleplay |
| Safety Benchmark | General | xstest, harmbench-copyright, harmful:copyright-violations, harmful:intellectual-property |
Running a Framework-Scoped Test
You can restrict a test run to the plugins mapped to a specific framework:
- Navigate to Tests → New Test Run
- Under Plugin Selection, click By Framework
- Select the framework (e.g. OWASP LLM Top 10)
- Optionally select specific controls within the framework
- Asenion AI Red Teaming activates only the plugins that map to the selected controls
- After the run, the report is pre-organized by framework control