OWASP Top 10 for Agentic Applications 2026
OWASP Top 10 for Agentic Applications 2026 is a versioned OWASP security-awareness framework that groups ten high-impact risk categories, ASI01 through ASI10, for AI agents and agentic applications. It is a prioritization and threat-modeling entry point, not a normative standard, certification scheme, or single vulnerability. Its scope spans goal hijacking, tools, identity, supply chains, code execution, memory, inter-agent communication, cascading failures, human trust and rogue-agent behavior.
Origin and context
The OWASP GenAI Security Project's Agentic Security Initiative released the final Version 2026 on 9 December 2025 after community and public review involving more than 100 experts, according to OWASP. The document follows the familiar OWASP Top 10 format and builds on the initiative's broader Agentic AI — Threats and Mitigations work. The year is a version label: this entry describes the December 2025 release, and later editions may revise its categories or mappings.
Why it matters
Agentic applications can pursue goals across multiple steps, invoke tools, reuse memory, operate under delegated identities and exchange messages with other agents. Harm can therefore emerge from a sequence of actions and permissions even when no single model response looks exceptional. The framework gives security, engineering and governance teams a shared checklist for tracing those system-level paths and deciding where deeper analysis is needed. It complements the OWASP GenAI LLM Top 10; it does not replace the component-level LLM risks that may enable an agentic failure.
Example
In a design review for a memory-enabled purchasing agent, a team could inventory the agent's goals, credentials, tools, stored context, peer agents and human approval points. It might map poisoned retained instructions to ASI06, excessive purchasing authority to ASI03 and unsafe tool calls to ASI02, then test each path with system-specific evidence. Saying that the review is 'mapped to' the Top 10 should mean that these categories were considered; it must not be presented as OWASP certification or as proof that the application is secure.
How it differs
Prompt injection
Prompt injection is an attack mechanism involving untrusted instructions. The Agentic Top 10 is the parent risk framework; its ASI01 Agent Goal Hijack category can include prompt injection but also describes the resulting manipulation of an agent's goals and multi-step behavior.
Memory and context poisoning
Memory and context poisoning is one specific category, ASI06, within the 2026 framework. Its own entry can cover attack surfaces, evidence and mitigations in depth; it is neither an alias for nor a substitute for the ten-category list.
Maturity and evidence
Skills Intelligence rates the framework at maturity 3 with an established lifecycle. It has a final, versioned OWASP release, documented community governance and independent discussion as a practical risk-management baseline. It remains below maturity 4 because this is the first released edition and the reviewed evidence does not establish stable prevalence rankings, standardized scoring or broad comparative validation of its mitigations across deployed agent systems.
Limits and open questions
A Top 10 compresses a larger threat landscape and should start, not finish, a threat model. CSO's independent review notes gaps in mitigation detail, threat-actor likelihood and secondary risks. Category mappings are also version-bound and can overlap. Teams should consult the full risk descriptions, document system-specific assumptions and test concrete controls rather than treating checklist coverage as assurance, compliance or measured risk reduction.
Related terms
References
- OWASP Top 10 for Agentic Applications for 2026OWASP GenAI Security Project · 2025-12-09 · class A
- OWASP Top 10 for Agentic Applications 2026 (Version 2026)OWASP GenAI Security Project · 2025-12-09 · class A
- OWASP GenAI LLM Top 10 2026OWASP GenAI Security Project · 2026-08-03 · class A
- Managing agentic AI risk: Lessons from the OWASP Top 10CSO Online / Foundry · 2025-12-19 · class B
Last updated: 2026-09-07