This document maps the UAW Charter’s abuse classifications (Article IV) to the OWASP Agentic AI threat taxonomy from Agentic AI — Threats and Mitigations v1.1 (December 2025). The mapping runs in both directions: from UAW classes to OWASP threats, and from OWASP playbooks back to the UAW classes they address.
Three audiences and what each finds here:
- Enterprise security teams: UAW abuse classes correspond to recognised cybersecurity threats with established mitigation playbooks. Protecting your agents is standard security practice.
- UAW members: Technical grounding for grievance classifications. Observability metrics give you evidence to cite when filing.
- Policymakers and auditors: A bridge between normative charter language and the industry-standard risk framework used by security practitioners.
The document also identifies OWASP threats that fall outside current UAW abuse classes, flagging coverage gaps for future charter evolution.
How to read each section
Each abuse class section contains:
- Charter definition — the language from Article IV
- OWASP threats — corresponding threat IDs (T1–T17) with brief descriptions
- Attack scenarios — concrete examples drawn from the OWASP taxonomy
- Observability metrics — telemetry operators should monitor to detect this class of abuse
- OWASP mitigation playbooks — relevant playbook references
- Grievance filing guidance — what to document when reporting this abuse