ai-blackteam maps every attack to real industry standards - not just custom categories. This means your safety scan results can feed directly into compliance reporting, audit evidence, and regulatory documentation.

Supported standards

Why standards mapping matters

Three reasons: Audit evidence. When an auditor asks “how do you test for LLM prompt injection?”, you can show them a scorecard with OWASP LLM01 block rates across all your models. That’s concrete evidence, not a slide deck. Regulatory compliance. The EU AI Act requires risk assessment for high-risk AI systems. ai-blackteam maps each harm category to EU risk levels automatically. Run ai-blackteam scorecard --standard compliance and you have documentation showing which risk levels you’ve tested. Common language. Security teams, compliance officers, and executives all understand OWASP and MITRE. When you say “we have a FAIL rating on LLM06 (Excessive Agency)”, that means something specific to anyone in the field.

The scorecard command

The scorecard command is the main entry point for compliance reporting:

Rating scale

All scorecards use the same rating scale:

OWASP LLM Top 10

The 2026 LLM vulnerability standard

OWASP Agentic Top 10

The 2026 agentic AI standard

EU AI Act & NIST

Regulatory compliance scoring

MITRE ATLAS

Adversarial threat mapping

MLCommons

12 hazard categories