As you may have heard, we convened key standardization organizations in DC two weeks ago, and established a coordination initiative called MOSAIC Multi-Organization Secure AI Coordination.
The communication platform the group decided on is GitHub, and since the OWASP AI Exchange has taken this initiative, and OWASP has built up a good name in AI security, we are going for an OWASP GitHub repo with the name MOSAIC.
I'd like you to be aware of this initiative because its impact is quite profound. OWASP is enabling collective coordination in the field, under its trusted open governance model.
To be clear:
- MOSAIC is not a collective - it is not a new identity
- MOSAIC is a coordination platform - lightweight
- MOSAIC is a first of its kind. What didn't happen for cyber security in general, is happening now for AI security
- The worst case scenario is that MOSAIC will be a map of initiatives in a standardized format, plus some issues to align on, such as terminology, with just a few initiatives. Great! The best scenario is that MOSAIC will be a thriving platform, brokering for experts and initiatives - fostering alignment and achieving 'one voice', with many organizations connected.
We'll see.
For the repo, I am working with Starr to setup a new project, which is the correct procedure. I'd like to ask you that when this project request is presented to you, to see how you can fastlane it. The reason is that the event has been more than 2 weeks ago, and I don't want any of the other organisations starting GitHub repos as an alternative. This is OWASP's window of opportunity and we should grab it.
Thanks.
Rob van der Veer
on behalf of the OWASP AI exchange