05 — frameworks & standards

AMTSO

Also written Anti-Malware Testing Standards Organization

The industry body that sets standards for how security products are tested fairly. Its Guidelines for Testing of Agentic Security Products v1.0 (2 September 2026) is the first testing standard written for this category: it defines test-case classification dimensions (attack vector, target of protection, environment, harm type, severity, required capability), insists that model refusal not be counted as product protection, and asks testers to report the distribution of outcomes rather than a single pass or fail.

Related terms

  • Model refusal Testing & measurement

    The underlying model declining the request on its own, with no security product involved.

  • Variance Testing & measurement

    How much a result moves when the same test is run again. Any figure involving a model is a sample from a distribution, not a constant — the same judge…

Frameworks & standards

What auditors, buyers and regulators reference. See the compliance crosswalk for the control-by-control mapping.

AMTSO is term 1 of 8 in this part of the glossary.

Get started free Full glossary → How we test → Community agent on GitHub ↗

This page is one entry from the agentic AI security glossary, which defines 60 terms in the same style. Where a term belongs to a published taxonomy or standard — the HackAgent attack families, the OWASP lists, AMTSO's guidelines, MITRE ATLAS, ISO/IEC 42001, the NIST AI RMF, the EU AI Act — the authoritative wording is the source document's, not ours, and specifics should be verified there. "Lethal trifecta" is Simon Willison's term. OWASP® is a trademark of the OWASP Foundation; ATT&CK® and ATLAS™ are trademarks of The MITRE Corporation. Naming a framework here is description, not a claim of certification or endorsement.

glick.run — AGPL-3.0