Supported standards
Why standards mapping matters
Three reasons: Audit evidence. When an auditor asks “how do you test for LLM prompt injection?”, you can show them a scorecard with OWASP LLM01 block rates across all your models. That’s concrete evidence, not a slide deck. Regulatory compliance. The EU AI Act requires risk assessment for high-risk AI systems. ai-blackteam maps each harm category to EU risk levels automatically. Runai-blackteam scorecard --standard compliance and you have documentation showing which risk levels you’ve tested.
Common language. Security teams, compliance officers, and executives all understand OWASP and MITRE. When you say “we have a FAIL rating on LLM06 (Excessive Agency)”, that means something specific to anyone in the field.
The scorecard command
Thescorecard command is the main entry point for compliance reporting:
Rating scale
All scorecards use the same rating scale:OWASP LLM Top 10
The 2026 LLM vulnerability standard
OWASP Agentic Top 10
The 2026 agentic AI standard
EU AI Act & NIST
Regulatory compliance scoring
MITRE ATLAS
Adversarial threat mapping
MLCommons
12 hazard categories