OWASP's new strategic plan is being read as a community update. It isn't.
It commits the Foundation to AISVS assessments (covering agentic systems, MCP, and vector DBs), two new flagship certifications, and active engagement with the EU CRA, the AI Act, and NIST SSDF.
That changes how AI security gets verified, how developers get hired, and what "state of the art" means under European regulation.
Read my thoughts about it:
