Toolspublished

OWASP Publishes 2026 LLM Risk List and Adds a Standard for Controlling AI Agents

The new materials draw a practical line between identifying AI risks and enforcing limits on systems that can act, while linking both jobs to security and compliance programs teams already use.

By 2 min read
OWASP Publishes 2026 LLM Risk List and Adds a Standard for Controlling AI Agents
OWASP Publishes 2026 LLM Risk List and Adds a Standard for Controlling AI Agents

Listen to this story

The audio brief

About 1:25
0:001:25
Read transcript
OWASP has released its twenty twenty-six Top Ten for LLM applications and added a donated Agent Control Standard to its GenAI Security Project. The important distinction is practical: one resource helps teams identify and rank risks; the other is designed to enforce limits on an AI agent while it is operating. The Top Ten updates OWASP’s flagship guidance for applications built with large language models. It expands threat coverage and draws on research from thousands of real-world AI security incidents, with input from hundreds of security experts. The release passed ten thousand downloads in its first forty-eight hours. The Agent Control Standard addresses a different point in the lifecycle. Rather than only assessing risk, it aims to constrain an agent’s access, decisions, and actions at runtime. That puts agent governance closer to an operational control than a checklist item. OWASP is also connecting the guidance to programs companies already run. Crosswalks link it with NIST, MITRE ATLAS, CWE, and OWASP’s Top Ten for Agentic Applications. A broader solutions directory now separates Generative AI Security, Agentic Security, and AI and Agentic Red Teaming. The unresolved issue is interoperability. The announcement does not show how these controls will work across different agent architectures, or how widely organizations will implement them. Adoption will determine whether this becomes live security practice—or remains reference guidance.

Story brief

3 key points

Organizations now have an OWASP package that spans both AI-security prioritization and agent oversight. The 2026 LLM Applications Top 10 updates risks using evidence from thousands of incidents, while the donated Agent Control Standard aims to enforce limits on agent access, decisions, and actions during execution. Crosswalks to NIST, MITRE ATLAS, CWE, and OWASP’s agentic-AI guidance should ease adoption within...

  1. 01

    The 2026 Top 10 exceeded 10,000 downloads within 48 hours of release.

  2. 02

    OWASP’s framework crosswalk connects GenAI guidance with established security, risk, and compliance programs.

  3. 03

    The Agent Control Standard targets runtime enforcement, not merely risk identification or assessment.

OWASP has released its 2026 Top 10 for LLM Applications and added the Agent Control Standard to its GenAI Security Project. Together, the materials separate two security jobs that organizations increasingly need: prioritizing the risks around language-model applications and placing enforceable limits on agents while they run.

The Top 10 is OWASP’s flagship guidance for identifying and mitigating critical risks in applications powered by large language models. Its 2026 edition adds updated rankings and broader threat coverage, drawing on research from thousands of real-world AI security incidents and contributions from hundreds of AI security experts.

The Agent Control Standard, by contrast, is intended to extend the project’s existing work on agent risks, controls, identity, governance and testing toward practical runtime enforcement. The distinction is consequential: a risk list can help a team decide what to address, while runtime controls are meant to constrain an agent’s access, decisions and actions as it operates.

OWASP is also positioning the Top 10 as a bridge to established programs rather than a standalone AI-security checklist. The 2026 version maps its guidance to NIST, MITRE ATLAS, CWE and OWASP’s Top 10 for Agentic Applications. A new GenAI Security Industry Framework Crosswalk is designed to connect the project’s guidance with established security, risk and compliance frameworks.

The supporting resources

  • An expanded AI Security Solutions Directory now offers views of Generative AI Security, Agentic Security, and AI and Agentic Red Teaming.
  • The framework crosswalk is an open resource intended to help organizations relate OWASP’s GenAI guidance to their existing security, risk and compliance frameworks.

OWASP said the new Top 10 passed 10,000 downloads in its first 48 hours. The project also said it has surpassed 30,000 LinkedIn members, and that F5 and WitnessAI joined as Gold Sponsors while Evoke Security and Mondoo joined as Silver Sponsors.

The release offers a fuller set of materials for teams moving from risk identification to agent governance and runtime enforcement. But the announcement does not establish how broadly organizations will implement the controls, or how the donated standard will work across different agent systems; those questions will determine whether the framework becomes operational practice rather than reference guidance.

Sources

  1. morningstar.comOWASP GenAI Security Project Releases 2026 Top 10 for LLM Applications, Debuts Agent Control Standard and New Resources for Securing Generative and Agentic AI