OWASP Top 10 for Agentic Applications 2026
Published on 9 December 2025 by the OWASP Agentic Security Initiative, this is the first Top 10 written for systems that plan and act rather than systems that answer. Its stated purpose is practical, actionable guidance for securing agents that plan, act and make decisions across complex workflows.
The verdict
Verified
The document exists. The ledger fetched it at its publisher and quotes it.
Key facts
What the sources say
- Record ID
- AAL-2026-0016
- Kind
- Guidance
- Jurisdiction
- Global
- Last verified
- Added
- OWASP describes the list as providing practical, actionable guidance to help organisations secure AI agents that plan, act, and make decisions across complex workflows.
- It sits alongside the Agentic Security Initiative's other outputs, including a practical guide for secure MCP server development.
- It is a community list, not a certification scheme or a control catalogue an auditor can test against.
- It gives security teams a shared vocabulary for classifying and reporting agentic threats.
Dimension by dimension
2 dimensions, each one stated, silent or open
Limits, Accountability. Stated means the document you can open below says it; silent means the ledger read the document and it does not.
- LimitsStated
- The list is organised around what an agent can reach and do, which makes the tool and permission inventory the first artefact a review needs.OWASP Gen AI Security Project, primary source, 9 December 2025.
- AccountabilityStated
- It gives a shared vocabulary for reporting agentic incidents, which is the precondition for anyone being answerable for one.OWASP Gen AI Security Project, primary source, 9 December 2025.
Figures
Every number, with who measured it and when
- 10 risks
Risks named in the list
OWASP Gen AI Security Project, primary source, as of .
What it changes
For a team deploying an agent
Use this as the threat model your agent design review runs against, the way web teams use the web Top 10. It will not satisfy a regulator on its own, but a review that cannot name which of these risks apply to your agent has not been a review.
Sources
What this record was verified against
- OWASP Gen AI Security ProjectPrimary · 9 December 2025
- OWASP Agentic Security InitiativePrimary · 15 September 2026
Related
Records that sit beside this one
OWASP Top 10 for LLM Applications 2025
Global · verified 15 September 2026
LLM01:2025 is Prompt Injection, where user prompts alter the behaviour or output of the model in unintended ways.
Model Context Protocol security best practices
Global · verified 15 September 2026
Token passthrough is an anti pattern where a server accepts a token from a client without validating it was issued to that server, and the document forbids it.
Does a spending limit belong to the agent or to the principal
Global · verified 15 September 2026
The Visa Trusted Agent Protocol addresses recognising an approved agent and its intent, and does not itself carry a spending ceiling.
How does a sub agent's authority attenuate
Global · verified 15 September 2026
RFC 8693 lets a token record that one party is acting for another, but does not require the exchanged token to be narrower.
Can an agent hold a credential of its own
Global · verified 15 September 2026
NIST SP 800-63-4 states that for that publication, person refers only to natural persons.
Who is liable when a delegated agent exceeds its mandate
Global · verified 15 September 2026
The EU AI Act allocates duties to providers and deployers, and does not address an agent acting beyond its instructions.
Cite this record
Free to reuse under CC BY 4.0, with attribution. The record ID AAL-2026-0016 is permanent and is never reused.
- In a sentence
- According to the GAGE Agent Authority Ledger (as of 15 September 2026), owasp top 10 for agentic applications 2026.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). OWASP Top 10 for Agentic Applications 2026. Agent Authority Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0016-owasp-top-10-for-agentic-applications-2026
- MLA
- "OWASP Top 10 for Agentic Applications 2026." Agent Authority Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0016-owasp-top-10-for-agentic-applications-2026.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "OWASP Top 10 for Agentic Applications 2026." Agent Authority Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0016-owasp-top-10-for-agentic-applications-2026.
- Permalink
- https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0016-owasp-top-10-for-agentic-applications-2026
Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any NIST, IETF or MCP publication.
Back to the full ledger, or every record for Global and every guidance record.
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.