The OWASP Agentic Risk Lists Explained
OWASP publishes three related lists for agent risk. Here is what Excessive Agency, the agentic threat taxonomy and the Agentic Top 10 each cover, and how they fit together.
Checked against primary sources and independently reviewed on . Sources are listed at the end.
OWASP, the Open Worldwide Application Security Project, is a volunteer community best known for its Top 10 list of web application risks. Its GenAI Security Project now maintains several documents that touch on AI agents, and they are easy to confuse. They use different numbering, were written for different purposes and have been revised at different times.
This article sorts them out. It explains the Excessive Agency entry in the Top 10 for LLM Applications, the longer agentic threat taxonomy, and the Top 10 for Agentic Applications released in December 2025. It then maps the agentic Top 10 onto the parts of an agent where each risk appears. For the general LLM list and attacks such as jailbreaking, see the AI Security group.
Three Documents, Three Jobs
- Top 10 for LLM Applications 2025
Includes LLM06:2025 Excessive Agency.
- Agentic AI: Threats and Mitigations, version 1.0
A detailed threat model for agents, with mitigations.
- Top 10 for Agentic Applications 2026
Ten entries, ASI01 to ASI10. Threats and Mitigations updated to version 1.1 the same month.
- LLM Top 10 2026
Excessive Agency moves up to third place.
- Agent Control Standard
A donated standard aimed at runtime enforcement.
The three core documents do different jobs. The LLM Top 10 is about applications built on language models in general. The threat taxonomy is a detailed reference for threat modelling. The agentic Top 10 is the short version that security leaders can use to set priorities, and OWASP says it relies on the taxonomy underneath it.1
Excessive Agency In The LLM Top 10
The 2025 edition of the LLM list was released in November 2024.2 Its entry LLM06:2025 Excessive Agency is about what happens when an application lets model output trigger real actions and that output turns out to be wrong, unclear or planted by an attacker. OWASP traces the problem to three root causes: excessive functionality, excessive permissions and excessive autonomy.3
The mitigations follow from those causes. Offer the model only the extensions it needs, and give each one only the functions it needs. Avoid open-ended tools, such as a general shell command or an arbitrary URL fetcher, when a narrow tool would do. Run actions with the minimum permissions and, where possible, in the context of the user making the request. Have a person approve high-impact actions, and let downstream systems decide what is allowed rather than leaving that judgement to the model.3
In the 2026 edition of the LLM list, released in August 2026, Excessive Agency is entry LLM03, up from sixth.4 The project leads explain that this was the first edition to test the practitioner vote against real incident data, with the vote carrying three quarters of the weight and the incidents one quarter. They call Excessive Agency’s rise to third the most consequential move in the list.5
The Agentic Threat Taxonomy
“Agentic AI: Threats and Mitigations” was first published as version 1.0 in February 2025.6 The current version, 1.1 from December 2025, lists 17 threats, T1 to T17.7 They range from memory poisoning (T1) and tool misuse (T2) to overwhelming the human in the loop (T10), rogue agents in multi-agent systems (T13), human manipulation (T15), insecure inter-agent protocol abuse (T16) and supply chain compromise (T17).
The taxonomy is where to go when you are building a threat model and need detail. Each threat has a description and suggested mitigations, and the document separates threats that are new to agents from older model risks that agents make worse.
The Top 10 For Agentic Applications
The agentic Top 10 was published on 9 December 2025 and developed with more than 100 contributors.8 Its entries are:
- ASI01 Agent Goal Hijack. Planted content redirects what the agent is trying to achieve.
- ASI02 Tool Misuse and Exploitation. The agent uses a legitimate tool, within its permissions, in a harmful way.
- ASI03 Identity and Privilege Abuse. Delegated credentials, inherited roles or cached sessions are used to gain access the agent should not have.
- ASI04 Agentic Supply Chain Vulnerabilities. Tools, models, plug-ins, other agents or protocol servers supplied by third parties are malicious or tampered with.
- ASI05 Unexpected Code Execution (RCE). Generated or injected code runs on a host or container.
- ASI06 Memory and Context Poisoning. Stored context, summaries or retrieval data are corrupted so later decisions go wrong.
- ASI07 Insecure Inter-Agent Communication. Messages between agents can be spoofed, altered or intercepted.
- ASI08 Cascading Failures. One fault spreads across agents and grows into system-wide harm.
- ASI09 Human-Agent Trust Exploitation. People over-trust a confident agent and approve harmful actions.
- ASI10 Rogue Agents. An agent drifts from its intended function and acts harmfully while appearing legitimate.
The document links each entry to older material. It notes that ASI02 builds on the LLM06 mitigations and extends them to multi-step workflows, and that ASI01 corresponds to taxonomy threats T6 and T7.1 It also introduces the idea of “least agency”: avoid giving systems autonomy they do not need.
Mapping The Top 10 To The Agent
A useful way to read the list is to ask where in the agent each risk happens. The table below is our own grouping, based on the entry descriptions. Some entries appear in more than one place.
| Entry | Inputs | Memory | Planning | Tools and code | Identity | Other agents | Humans |
|---|---|---|---|---|---|---|---|
| ASI01 Goal Hijack | Yes | Yes | Yes | ||||
| ASI02 Tool Misuse | Yes | ||||||
| ASI03 Identity and Privilege | Yes | Yes | |||||
| ASI04 Supply Chain | Yes | Yes | |||||
| ASI05 Code Execution | Yes | ||||||
| ASI06 Memory Poisoning | Yes | Yes | |||||
| ASI07 Inter-Agent | Yes | Yes | |||||
| ASI08 Cascading Failures | Yes | Yes | |||||
| ASI09 Trust Exploitation | Yes | ||||||
| ASI10 Rogue Agents | Yes | Yes |
Read this way, the list falls into a few clusters. Goal hijack and memory poisoning are about what enters the agent’s context. Tool misuse, identity abuse and code execution are about what the agent can do once it is steered. Insecure inter-agent communication needs more than one agent, and cascading failures and rogue agents become much harder to contain once several agents work together. Trust exploitation is about the person at the approval screen.
How To Use The Lists
Treat the agentic Top 10 as a checklist for reviews and conversations with suppliers, and the threat taxonomy as the detailed reference for threat modelling. Joint government guidance from May 2026 points in the same direction, recommending threat modelling with current taxonomies such as those from the OWASP GenAI Security Project and MITRE ATLAS.9
Expect change. OWASP released an updated LLM list, a framework crosswalk and a donated Agent Control Standard in August and September 2026 alone.8 Check the version and date of any OWASP document you quote.
Footnotes
-
OWASP GenAI Security Project, “OWASP Top 10 for Agentic Applications 2026” (full document), December 2025. genai.owasp.org ↩ ↩2 ↩3
-
OWASP GenAI Security Project, “OWASP Top 10 for LLM Applications 2025”, resource page, 17 November 2024. genai.owasp.org ↩
-
OWASP GenAI Security Project, “LLM06:2025 Excessive Agency”, Top 10 for LLM Applications 2025. genai.owasp.org ↩ ↩2
-
OWASP GenAI Security Project, “OWASP Top 10 for LLM Applications 2026”, canonical source files, August 2026. github.com ↩
-
S. Wilson and R. Lambros, “Letter from the Project Leads”, OWASP Top 10 for LLM Applications 2026, August 2026. github.com ↩
-
OWASP GenAI Security Project, “Agentic AI: Threats and Mitigations”, version 1.0, 17 February 2025. genai.owasp.org ↩
-
OWASP GenAI Security Project, “Agentic AI: Threats and Mitigations”, version 1.1, December 2025. genai.owasp.org ↩
-
OWASP GenAI Security Project, “OWASP Top 10 for Agentic Applications for 2026”, 9 December 2025. genai.owasp.org ↩ ↩2
-
ASD’s ACSC, CISA, NSA, Canadian Centre for Cyber Security, NCSC-NZ and NCSC-UK, “Careful Adoption of Agentic AI Services”, 1 May 2026. ncsc.govt.nz ↩
Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.