skip to content

Why does OWASP publish a separate Agentic Top 10 alongside the GenAI LLM Top 10?

level: middleimportance: should knowfreq 52%

answer

  1. one list assumes request and response
  2. the other assumes plans, memory, tools, peers
  3. ASI01 goal hijack through ASI10 rogue agents
  4. vector and memory flaws is the 2026 addition
  5. coverage checklist, never a control catalogue

basics

~20 s

The LLM Top 10 models a prompt-in, text-out application. The Agentic Top 10 covers what appears only when a system plans, keeps memory across sessions, calls tools and talks to other agents — goal hijack, tool misuse, memory poisoning, rogue agents.

solid answer

~50 s

They are two coverage checklists for two system shapes, and a serious register uses both when the product is agentic. The GenAI LLM Top 10 2026 keeps the risks of a model-in-an-application: prompt injection at LLM01, sensitive information disclosure at LLM02, improper output handling, plus newer entries reflecting how apps are actually built — vector and memory flaws, hidden context exposure, unbounded consumption. The Agentic list, ASI01 to ASI10, names what only exists once the model acts over time and across systems: agent goal hijack, tool misuse, identity and privilege abuse, agentic supply chain, unexpected code execution, memory and context poisoning, insecure inter-agent communication, cascading failures, human-agent trust exploitation, and rogue agents. They overlap deliberately — goal hijack is injection with persistence and consequence — and both carry mappings to NIST and MITRE ATLAS so the entries land in the org's existing risk register.

go deeper

for a junior

Recognize that OWASP publishes AI risk lists and that prompt injection sits at the top of the LLM one. Naming a few categories confidently is enough at this level.

for a middle

Explain why two lists exist — planning, persistent memory, tools and inter-agent messaging create risks a single request cannot have — and name several entries from each without reciting the whole list.

for a senior

Show you can run the checklist against a real data flow and produce findings with owners, including well-reasoned not-applicable entries, rather than a coverage percentage.

for a principal

Own the fit into the wider risk function: the NIST and ATLAS mappings, the argument for why agentic risks are not a separate silo, and the standard your org holds a product to before it gets tool access.

## Two lists, two system shapes OWASP's GenAI risk lists were re-cut in December 2025 into a pair rather than one. The reason is that the original list was written for an application that takes a prompt, maybe retrieves some documents, and returns text. That system's risks are about what goes into the prompt and what comes out of it. An agentic system adds three properties the older list never assumed: it **plans over multiple steps**, it **retains state between sessions**, and it **acts on the world through tools and other agents**. Each of those creates failure modes that have no analogue in a single request. ## What the LLM Top 10 2026 carries The 2026 revision keeps **LLM01 Prompt Injection** and **LLM02 Sensitive Information Disclosure** at the top, elevates **Excessive Agency** — the risk that the system can take actions beyond what the task requires — and adds or broadens entries that reflect how applications are now built: - **LLM07 Vector and Memory Flaws**, new in 2026, covering poisoned, leaky or cross-tenant retrieval indexes and memory stores. Its arrival is an admission that RAG and persistent memory are now default architecture, not an advanced option. - **LLM09 Hidden Context Exposure**, which broadens the older System Prompt Leakage entry to cover everything the user never sees but the model does: system instructions, injected policies, tool definitions, retrieved spans. - **LLM10 Unbounded Consumption**, the renamed and widened successor to model denial of service, covering runaway cost and resource exhaustion as well as availability. - Improper output handling, which is the classic sink problem: model output parsed as markup, SQL or shell by something downstream. ## What the Agentic Top 10 adds The Top 10 for Agentic Applications runs ASI01 to ASI10: - **ASI01 Agent Goal Hijack** — the agent's objective is redirected mid-run, typically by content it reads. - **ASI02 Tool Misuse** — a legitimately available tool used for an illegitimate end. - **ASI03 Identity and Privilege Abuse** — the agent operating with more authority than the task or the requesting human holds. - **ASI04 Agentic Supply Chain** — risk inherited from third-party tools, servers, skills and agents the system pulls in. - **ASI05 Unexpected Code Execution** — the agent generating and running code paths nobody reviewed. - **ASI06 Memory and Context Poisoning** — hostile content written into durable memory and recalled in later, unrelated sessions. - **ASI07 Insecure Inter-Agent Communication** — messages between agents treated as trusted because they came from a peer. - **ASI08 Cascading Failures** — one bad output propagating through a chain of dependent agents or steps. - **ASI09 Human-Agent Trust Exploitation** — the human overtrusting a confident agent, including approval fatigue on review gates. - **ASI10 Rogue Agents** — agents running outside intended supervision or scope. The list is published with mappings to NIST material and to MITRE ATLAS, which matters practically: it lets an AI finding sit in the same register, with the same vocabulary, as the rest of the organisation's risk. ## They overlap on purpose ASI01 goal hijack is prompt injection viewed through the agentic lens — same entry mechanism, but the consequence is a redirected multi-step plan with tool access rather than one bad paragraph. ASI06 memory poisoning is indirect injection that persists past the session that planted it. This overlap is a feature: the two lists ask you the same question at two different consequence scales, and an agentic product should answer both. ## How to use them Use them as **coverage checklists, not as a control catalogue**. Neither list tells you what to build; both tell you what you may have failed to consider. The productive pass is mechanical: take your data-flow map, walk each entry, and answer three questions — does this apply to us, what is the realizable worst case, who owns the mitigation. Entries that genuinely do not apply are recorded as not-applicable with the reason, because "we considered vector and memory flaws and have no persistent store" is a defensible position and a silent omission is not. On a plant-maintenance copilot that reads supplier manuals and work orders and can schedule a line shutdown, the pass produces very different findings from each list. From the LLM list: a supplier-uploaded manual poisoning the index every technician queries (vector and memory flaws), and a malformed manual triggering a repeated 400-page re-summarization across every shift (unbounded consumption). From the agentic list: the copilot closing a work order without an engineer's sign-off (excessive agency and identity abuse), and a technician approving a shutdown request because the agent stated its reasoning fluently (human-agent trust exploitation). ## What the lists are not They are not a maturity score, not a compliance certification, and not ranked by your risk — the numbering reflects community-wide prevalence, not the priority order for your system. A team that reports "we cover eight of ten" has misused them. The output of the pass should be findings with owners and a residual-risk position, not a tally.

  • Your product is a single-turn summarizer with no tools. Do you still walk the agentic list?
    Walk it once, quickly, and record most entries as not applicable with the reason. That record is the value: it proves the omission was a decision, and it becomes the tripwire when someone later adds a tool call or a memory store. The moment the summarizer gains an action or persistence, the entries you dismissed become live, and you want the earlier reasoning on file rather than starting from scratch.
  • How do prompt injection and agent goal hijack differ, given they overlap?
    The entry mechanism is the same — hostile text reaching the context. The difference is consequence and duration. Injection in a chat app produces a bad response. Goal hijack redirects a multi-step plan that holds tool access, so the damage compounds across steps and may persist into later runs if the redirected objective is written to memory. Modeling them separately keeps the blast-radius question in view.
  • Why does the 2026 LLM list add a vector and memory category at all?
    Because retrieval and persistent memory became default architecture, and their failure modes are not covered by the input and output entries. A poisoned index is an injection vector that outlives any single request; a badly scoped memory store leaks across tenants and sessions without any prompt being involved. Giving it its own entry forces teams to model the store as an asset with writers and readers of its own.

saying these in an interview costs you the question

  • Treats the OWASP numbering as a priority order for their own system
  • Reports coverage as a score instead of findings with owners
  • Assumes the LLM Top 10 already covers agent-specific risks
  • Thinks the lists prescribe specific controls to implement
  • Skips the agentic list for a product that has tools and memory

context