What matters in AI.

Subscribe

Learn / AI agents

Definition · AI agents

OWASP Top 10 for Agentic Applications

The OWASP Top 10 for Agentic Applications, or OWASP Agentic Top 10, is a list of the ten most critical security risks in AI agents: systems that plan, call tools, keep memory and act across several steps. The OWASP GenAI Security Project published it in December 2025, numbering its entries ASI01 Agent Goal Hijack to ASI10 Rogue Agents.

Last reviewed

Key points

  • Published 9 December 2025 as the 2026 edition. OWASP credits more than 100 industry experts, researchers and practitioners.
  • It covers the model as an actor. OWASP's LLM Top 10 covers the model as a component and hands over once the model has tools and memory.
  • Each entry says where it stops. Cascading Failures, for example, is the spread of a fault, not the fault itself.
  • Its entries cite 2025 LLM IDs, and some have moved. LLM06:2025 Excessive Agency is LLM03 in 2026.
  • OWASP's Least-Agency advice, an extension of least privilege, is to give an agent no more autonomy than the task needs.

What is on the list

ID Entry Topic
ASI01 Agent Goal Hijack Agent hijacking
ASI02 Tool Misuse and Exploitation
ASI03 Identity and Privilege Abuse Agentic identity and privilege abuse
ASI04 Agentic Supply Chain Vulnerabilities AI supply chain compromise
ASI05 Unexpected Code Execution (RCE) Unexpected code execution
ASI06 Memory and Context Poisoning Agent memory poisoning
ASI07 Insecure Inter-Agent Communication Insecure inter agent communication
ASI08 Cascading Failures Cascading failures
ASI09 Human-Agent Trust Exploitation Human agent trust exploitation
ASI10 Rogue Agents Rogue agents

Where each entry stops

One incident can touch several entries, so each marks its edge.

  • Tool, privilege or code. ASI02 is an allowed tool used harmfully, ASI03 is gaining privileges, and ASI05 is running arbitrary code.
  • Goal or memory. ASI01 is an attacker changing the agent’s goal. ASI06 is an adversary corrupting the agent’s stored memory or context.
  • Trigger or spread. A tainted dependency, poisoned memory or spoofed message is ASI04, ASI06 or ASI07. ASI08 applies only once that fault spreads across agents, sessions or workflows with measurable impact.
  • Agent or human. ASI10 is the agent’s own behavior drifting. ASI09 is an attacker or a flawed design exploiting a person’s trust in an agent to steer their decisions.

Why it matters

The OWASP LLM Top 10 covers the model as a component, says its 2026 preface. Once the model acts, with tools and memory, the risk moves to the Agentic Top 10. Many incidents straddle both, so OWASP says to use both for a model that acts.

The list’s leaders write that “Agents amplify existing vulnerabilities”. A prompt injection that once changed one answer can now redirect many actions.

Their advice includes Least-Agency, which extends least privilege and excessive agency: unneeded autonomy widens the attack surface without adding value.

Using the list

Mind the LLM IDs inside it. The Agentic list cites the 2025 LLM Top 10, and some of those IDs have since moved. ASI02 and ASI03 both build on LLM06:2025 Excessive Agency, which is LLM03 in the 2026 LLM list. LLM01 Prompt Injection kept its number. The 2026 LLM list maps its own entries to ASI IDs in an appendix, so the two lists now map to each other in both directions.

Read the prefix. ASI stands for OWASP’s Agentic Security Initiative, which wrote the list.

It is the short version. The list’s leaders call the Top 10 a compass. The detailed taxonomy it relies on is OWASP’s Agentic AI Threats and Mitigations, and each entry names the threat IDs it maps to there. An appendix also maps every entry to the 2025 LLM list and to OWASP’s AI Vulnerability Scoring System (AIVSS).

It keeps an incident tracker. Appendix D lists real exploits and incidents against the ASI entries they illustrate.

Do not confuse it with AST10. The OWASP Agentic Skills Top 10 is a separate OWASP list about agent skills, with IDs AST01 to AST10.

Questions and answers

What are the OWASP Top 10 for Agentic Applications?

ASI01 Agent Goal Hijack, ASI02 Tool Misuse and Exploitation, ASI03 Identity and Privilege Abuse, ASI04 Agentic Supply Chain Vulnerabilities, ASI05 Unexpected Code Execution, ASI06 Memory and Context Poisoning, ASI07 Insecure Inter-Agent Communication, ASI08 Cascading Failures, ASI09 Human-Agent Trust Exploitation and ASI10 Rogue Agents. OWASP published the list in December 2025 as the 2026 edition.

What is the difference between the OWASP Agentic Top 10 and the LLM Top 10?

The LLM Top 10 covers a language model as a component inside an application. The Agentic Top 10 covers the model once it acts, with tools it can call and memory it keeps between sessions. OWASP's 2026 LLM preface says many incidents fall on the boundary and advises using both lists once a model acts on its own.

Is the OWASP Agentic Top 10 the same as AST10?

No. AST10, the OWASP Agentic Skills Top 10, is a separate OWASP project about agent skills, with IDs AST01 to AST10. Its whitepaper warns readers not to confuse those with ASI01 to ASI10, the IDs of the Agentic Top 10.

What is Least-Agency?

OWASP's advice, in the Agentic Top 10, to avoid giving an agent autonomy it does not need. OWASP presents it as an expansion of least privilege and excessive agency, because agentic behavior deployed where it is not needed widens the attack surface without adding value.

Sources

  1. OWASP Top 10 for Agentic Applications for 2026, resource pageOWASP GenAI Security Project, 9 Dec 2025
  2. OWASP Top 10 for Agentic Applications 2026OWASP GenAI Security Project, 9 Dec 2025
  3. OWASP Top 10 for LLM Applications 2026, LLM00 PrefaceOWASP GenAI Security Project, 4 Aug 2026
  4. OWASP Top 10 for LLM Applications 2026, Appendix A Related Framework MappingsOWASP GenAI Security Project, 4 Aug 2026
  5. OWASP Agentic Skills Top 10, V1 whitepaperOWASP

Guides that use this term