Skip to main content
VerifiedGuidance

OWASP Top 10 for Agentic Applications 2026

Published on 9 December 2025 by the OWASP Agentic Security Initiative, this is the first Top 10 written for systems that plan and act rather than systems that answer. Its stated purpose is practical, actionable guidance for securing agents that plan, act and make decisions across complex workflows.

The verdict

Verified

The document exists. The ledger fetched it at its publisher and quotes it.

Key facts

What the sources say

Record ID
AAL-2026-0016
Kind
Guidance
Jurisdiction
Global
Last verified
Added
  • OWASP describes the list as providing practical, actionable guidance to help organisations secure AI agents that plan, act, and make decisions across complex workflows.
  • It sits alongside the Agentic Security Initiative's other outputs, including a practical guide for secure MCP server development.
  • It is a community list, not a certification scheme or a control catalogue an auditor can test against.
  • It gives security teams a shared vocabulary for classifying and reporting agentic threats.

Dimension by dimension

2 dimensions, each one stated, silent or open

Limits, Accountability. Stated means the document you can open below says it; silent means the ledger read the document and it does not.

LimitsStated
The list is organised around what an agent can reach and do, which makes the tool and permission inventory the first artefact a review needs.OWASP Gen AI Security Project, primary source, 9 December 2025.
AccountabilityStated
It gives a shared vocabulary for reporting agentic incidents, which is the precondition for anyone being answerable for one.OWASP Gen AI Security Project, primary source, 9 December 2025.

Figures

Every number, with who measured it and when

  1. 10 risks

    Risks named in the list

    OWASP Gen AI Security Project, primary source, as of .

What it changes

For a team deploying an agent

Use this as the threat model your agent design review runs against, the way web teams use the web Top 10. It will not satisfy a regulator on its own, but a review that cannot name which of these risks apply to your agent has not been a review.

Sources

What this record was verified against

  1. OWASP Gen AI Security ProjectPrimary · 9 December 2025
  2. OWASP Agentic Security InitiativePrimary · 15 September 2026

Related

Cite this record

Free to reuse under CC BY 4.0, with attribution. The record ID AAL-2026-0016 is permanent and is never reused.

In a sentence
According to the GAGE Agent Authority Ledger (as of 15 September 2026), owasp top 10 for agentic applications 2026.
APA
GAGE (Global Academy of Generative-AI Education). (2026). OWASP Top 10 for Agentic Applications 2026. Agent Authority Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0016-owasp-top-10-for-agentic-applications-2026
MLA
"OWASP Top 10 for Agentic Applications 2026." Agent Authority Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0016-owasp-top-10-for-agentic-applications-2026.
Chicago
GAGE (Global Academy of Generative-AI Education). "OWASP Top 10 for Agentic Applications 2026." Agent Authority Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0016-owasp-top-10-for-agentic-applications-2026.
Permalink
https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0016-owasp-top-10-for-agentic-applications-2026

Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any NIST, IETF or MCP publication.

Back to the full ledger, or every record for Global and every guidance record.

GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.