Machine intelligence · Agentic AI · Governed swarm management

Standards guide · Agentic security

OWASP Top 10 for Agentic Applications: operating translation

The OWASP Agentic Top 10 is a threat vocabulary, not a security stamp. Use it to drive threat models, scenarios, control design, evidence, and incident preparation across the full agentic system.

EnterpriseGovernmentPartners

Published Updated Reviewed By LongTermIntelligence.com

Direct answer

What is the OWASP Top 10 for Agentic Applications?

#

It is an OWASP GenAI Security Project taxonomy of ten major risk areas for applications in which AI agents plan, use tools, communicate, retain context, and act. The list creates a shared threat vocabulary; secure deployment still requires a scoped threat model, architecture, testing, monitoring, incident response, and evidence.

  • Apply the taxonomy to the complete system, not only the language model.
  • Test handoffs, identity, memory, tools, code execution, human review, and cascades.
  • Record which risks are in scope, which controls address them, and what evidence verifies the controls.

Source basis: reviewed official references are listed on this page and in the source ledger. Interpretation and implementation guidance retain the stated assurance boundary.

Risk-to-control map

The ten risk areas and their operating implications

The following labels follow the official OWASP list; the control translation is LongTermIntelligence.com guidance.

IDRisk areaOperating concernControl direction
ASI01Agent Goal HijackUntrusted content or interactions redirect the agent from its intended objective.Constrain goals, isolate instructions from data, validate state transitions, and test indirect injection.
ASI02Tool Misuse and ExploitationA legitimate tool is invoked with unsafe intent, parameters, sequence, or context.Use allowlists, typed contracts, policy checks, simulations, limits, and approval for consequential actions.
ASI03Identity & Privilege AbuseAgent identities or delegated credentials exceed the task, persist too long, or are misused.Issue task-scoped identity, least privilege and least agency, short-lived credentials, and auditable delegation.
ASI04Agentic Supply Chain VulnerabilitiesModels, prompts, tools, connectors, MCP servers, libraries, or data dependencies are compromised.Maintain an AIBOM, verify provenance, pin versions, monitor suppliers, and design replacement paths.
ASI05Unexpected Code ExecutionNatural-language inputs lead to unapproved code or command execution.Separate reasoning from execution, sandbox code, deny egress by default, and verify proposed side effects.
ASI06Memory & Context PoisoningMalicious or erroneous content persists in memory and influences later behavior.Validate writes, isolate memory domains, preserve provenance, expire data, and support rollback.
ASI07Insecure Inter-Agent CommunicationMessages are spoofed, altered, over-trusted, or lack identity and integrity.Authenticate agents, type messages, validate schemas and semantics, and trace every handoff.
ASI08Cascading FailuresA failure propagates through agents, tools, data, or workflows with increasing impact.Limit blast radius, checkpoint state, use circuit breakers, verify handoffs, and rehearse recovery.
ASI09Human-Agent Trust ExploitationPersuasive output causes people to approve harmful or unsupported actions.Show evidence and uncertainty, tier authority, design review workload, and test for automation bias.
ASI10Rogue AgentsAn agent acts outside intended control because of misalignment, compromise, or persistent autonomy.Maintain registries, runtime policy, containment, kill paths, independent monitoring, and retirement controls.

Threat-model workflow

Use the Top 10 as an evidence-producing process

A list of risks is not a completed threat model.

  1. Model the system

    Inventory agents, identities, models, prompts, tools, MCP servers, data, memory, messages, environments, people, and side effects.

  2. Trace trust boundaries

    Identify where untrusted input becomes instructions, privileges cross boundaries, state persists, or external systems are mutated.

  3. Create abuse and failure scenarios

    Map relevant ASI categories to realistic attacker, accident, dependency, and human-factor scenarios.

  4. Layer controls

    Combine preventive, detective, responsive, and recovery controls rather than relying on prompts or filters alone.

  5. Generate evidence

    Capture test results, traces, policy decisions, incidents, residual risk, and owner approval.

  6. Repeat after change

    Reassess when models, tools, prompts, permissions, memory, protocols, or workflow topology change.

Primary-source basis

Official references

Use the named primary sources for current definitions, dates, versions, and scope.

OWASP GenAI Security Project · Official Security Taxonomy

OWASP Top 10 for Agentic Applications

A community-developed taxonomy covering ten major agentic application risk areas, from goal hijacking and tool misuse through memory poisoning, cascading failures, and rogue agents.

Status
Current
Published
2025-12-09
Reviewed
2026-08-01

Use boundary: Use as a threat-oriented taxonomy and mitigation aid, not as a certification or guarantee of security.

Open official source

OWASP Foundation · Official Project Hub

OWASP GenAI Security Project

Official project hub for OWASP GenAI and agentic security resources, initiatives, guidance, and updates.

Status
Current
Reviewed
2026-08-01

Use boundary: Confirm the latest project documents and versions before using specific taxonomy labels.

Open official source

Official-source citations establish provenance and scope. They do not establish LongTermIntelligence.com certification, endorsement, legal advice, client outcomes, or a guarantee that a control is effective.

Private local search

Find machine intelligence, agentic AI, swarm management, services, industries, use cases, definitions, or research

Press / to open search when focus is not in a form field.

Search runs locally against the public site index.