Skip to content
View emmanuelgjr's full-sized avatar

Block or report emmanuelgjr

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
emmanuelgjr/README.md

Turning GenAI Risk into Auditable Controls

I'm Emmanuel Guilherme — an AI security leader who thinks like an auditor. I lead the Data Security Initiative (DSGAI) of the OWASP GenAI Security Project, co-lead LLM02 (Sensitive Information Disclosure) on the OWASP Top 10 for LLM Applications, and serve as a Candidate Expert on Canada's mirror committee for ISO/IEC JTC 1/SC 42 — the committee behind ISO/IEC 42001, 23894, and 42005. By day: Senior Global IT Auditor at Martinrea International (Tier 1 automotive).

Work I've contributed to at OWASP is cited in joint AI security guidance from the governments of the USA, Canada, the UK, Australia, and New Zealand, and referenced by CISA on agentic AI adoption.

I work where AI security meets enterprise audit reality. The repos here are open-source controls, mappings, and tooling that translate emerging GenAI risks into language CISOs, auditors, and regulators can act on.

Based in North America. Trilingual: English, Portuguese, Spanish.


Standards & community

  • OWASP GenAI Security Project — Lead, Data Security Initiative (DSGAI01–DSGAI21): one of three principal authors, driving a global community of 240+ contributors.
  • OWASP Top 10 for LLM Applications — Co-lead, LLM02 (Sensitive Information Disclosure); author of Persistent Memory Poisoning, a candidate entry for the next edition.
  • ISO/IEC JTC 1/SC 42 (Canada Mirror Committee) — Candidate Expert on AI standards (42001 · 23894 · 42005).
  • Threat Modeling Connect, Toronto Chapter — Co-founder.
  • Packt — AI Security Technical Reviewer (LLM security · adversarial ML · AI threat modeling).

Publications


Recognition

  • Cited by CISACareful Adoption of Agentic AI Services.
  • Featured in Lakera's GenAI Security Readiness Report (2024, 2025).
  • Quoted in the AIRQ (AI Risk Quadrant) framework alongside leaders from CSA and CoSAI.

AI security portfolio — v0.2 (June 2026)

Four sibling repos covering the governance, audit, offensive, and shadow-AI sides of enterprise AI security. Standards-aligned across ISO/IEC 42001, NIST AI RMF, EU AI Act, OWASP, MITRE ATLAS, SOC 2, OSFI E-21, and NYDFS Part 500. MIT-licensed code, CC-BY 4.0 content. All browser-only — no backend, no telemetry — each installable as an offline-capable PWA.

AI-Governance-Toolkit · live app — Stand up AI governance by Friday. AI system inventory with EU AI Act risk classification, AI Impact Assessment per ISO/IEC 42005, risk register with heatmaps, vendor risk questionnaire (40 weighted questions, red-flag detection), maturity self-assessment (8 domains, radar chart, action plan), interactive ISO/IEC 42001 roadmap (52-week tracker), and 12 downloadable templates. Word/Excel export.

AI-Controls-Catalog · live app — Audit-ready controls library for AI systems. 20 controls across 14 categories with Test of Design and Test of Operating Effectiveness guidance, sample-size direction, evidence requirements, and mappings to 10 frameworks. Scoping wizard (6-step questionnaire → tailored control set), RCM Excel export (4-worksheet working paper), Word/PDF/CSV/JSON export.

AI-RedTeam-Framework · live app — Stand up an AI red team at a regulated enterprise. 15-chapter playbook (charter → maturity model), 25 attack patterns mapped to OWASP LLM/Agentic Top 10, MITRE ATLAS, and NIST AI RMF, 15 candid tool reviews, 10 downloadable templates, and an interactive Engagement Planner that generates Word Rules of Engagement.

Shadow-AI-Defense · live app — Detect and respond to Shadow AI in your enterprise. 35 cataloged AI services with network and client signatures, 30 detection rules (Sentinel KQL, Defender for Cloud Apps, Defender for Endpoint, Purview DLP, CrowdStrike Falcon, Netskope, Zscaler, Conditional Access, generic network), 8 graduated response runbooks with RACI matrices, 8 security stack profiles, communications templates, and a policy starter.


Other featured projects

GenAI & Agentic AI Incidents12,500+ documented GenAI and agentic AI security incidents, each cross-referenced to OWASP LLM Top 10 (2025), Agentic Top 10, NIST AI RMF, and MITRE ATLAS. DOI-registered (10.5281/zenodo.20248676), published on PyPI and Hugging Face, with STIX 2.1, TAXII, and MISP feeds for threat-intel platforms.

GenAI-Security-Crosswalk — Open-source mapping of OWASP GenAI risks — LLM Top 10, Agentic Top 10, and DSGAI 2026 — to 25 industry frameworks, including NIST AI RMF, ISO/IEC 42001, EU AI Act, MITRE ATLAS, and OT/ICS guidance. 3,351 mappings across 1,016 controls; also published on npm.

DSGAI — Interactive web guide for the OWASP GenAI Data Security Risks and Mitigations 2026 publication I lead — 21 risk entries (DSGAI01–DSGAI21) with a three-tier mitigation model. Companion repo: GenAI-Data-Security-Initiative — taxonomies, crosswalks, datasets, and tooling for securing data in GenAI systems.

GenAI-Security-Literature-Review — Community-driven, auto-updating literature review of GenAI/LLM security research. 240+ curated entries across 46 categories, with weekly automated discovery from arXiv, Semantic Scholar, and CrossRef.

finagent-redrange — Reproducible, defensive red-team range for financial-services AI agents: nine proof-of-concept exploits against a mock banking agent — covering the full OWASP LLM Top 10 — each paired with the control that blocks it and mapped to MITRE ATLAS and NIST AI RMF.

AgentVulnMitigatoragentvuln, a runtime guardrail SDK for agentic AI. Normalizes evasive input (zero-width characters, confusables, base64, spacing tricks) and blocks prompt injection, jailbreaks, data exfiltration, and unsafe tool arguments before they reach the model or its tools.


Focus areas

  • Data security for GenAI — DSGAI 2026 (training data governance, inference-time leakage, RAG, agentic workflows)
  • LLM & agentic AI risk — prompt injection, tool misuse, autonomy scope, multi-agent threat modeling
  • AI governance & audit — ISO/IEC 42001, NIST AI RMF, EU AI Act, MITRE ATLAS, audit-ready control mappings
  • Shadow AI & enterprise controls — detection engineering, DLP, OT/ICS implications of AI deployment

Elsewhere

Pinned Loading

  1. genai_incidents genai_incidents Public

    Single source of truth for GenAI and agentic AI security incidents, mapped to OWASP LLM Top 10, OWASP Agentic Top 10 (ASI), NIST AI RMF, and MITRE ATLAS.

    Python 27 6

  2. GenAI-Security-Crosswalk GenAI-Security-Crosswalk Public

    The most comprehensive open-source mapping of OWASP GenAI risks to industry frameworks - 70 mapping files, 25 frameworks, 1,016 controls, 125 incidents, ML classifier pipeline. Source lists: LLM To…

    JavaScript 9 2

  3. DSGAI DSGAI Public

    OWASP GenAI Data Security Risks and Mitigations 2026 - Interactive web guide for 21 DSGAI risk entries

    JavaScript 3

  4. GenAI-Security-Literature-Review GenAI-Security-Literature-Review Public

    Comprehensive, auto-updating literature review of GenAI & LLM security research, standards, tools, and resources. 100+ curated entries with interactive webapp.

    Python 6 1

  5. GenAI-Security-Project/GenAI-Data-Security-Initiative GenAI-Security-Project/GenAI-Data-Security-Initiative Public

    OWASP GenAI Data Security Initiative — taxonomies, crosswalks, datasets, and tooling for securing data in generative AI systems

    JavaScript 15 9

  6. finagent-redrange finagent-redrange Public

    Reproducible, defensive red-team range for financial-services AI agents: 5 POC exploits against a mock banking agent, each proven blocked by its control and mapped to OWASP / MITRE ATLAS / NIST AI …

    Python