OWASP Top 10 for Agentic Applications 2026
Agent threat catalogue (ASI01 Agent Goal Hijack … ASI10 Rogue Agents)
AIGE-OBL-OWASP-AGENTIC. Drawn from chapter 08.
Text alternative
- Clause: OWASP Agentic, Top 10 for Agentic….
- Duty holder: Not stated.
- Applies from: No date, Voluntary.
- Artefact: Agent threat model.
- Layers: Layer 03, Layer 04.
- Evidence record: Evidence record v1.
- Record schema: Evidence record.
- The same topic in 21 other frameworks; the crosswalk section below links each clause.
- Id
AIGE-OBL-OWASP-AGENTIC- Instrument
- OWASP Top 10 for Agentic Applications 2026 framework
- Clause
- Top 10 for Agentic Applications 2026
- Applies from
- No date Voluntary · Voluntary (2026 edition)
The artefact that evidences it
Agent threat model; adversarial evals; runtime guardrails; kill switch.
Patterns that build it
- Policy Card (layer 1)
- Eval Gate in CI (layer 3)
- Adversarial Red-Team Suite (layer 3)
- Agent Registry (layer 2)
- Runtime Guardrail (layer 4)
- Kill Switch / Circuit Breaker (layer 4)
- Agent Identity & Scoped Credentials (layer 4)
- Human-in-the-loop Gate (layer 4)
- Shadow-AI Discovery (layer 2)
- AI Threat Model (layer 1 and 3)
- Model Artefact Integrity (layer 2 and 4)
- Downstream Use Register (layer 2 and 1)
- Deactivation, Localisation & Retirement Runbook (layer 4 and 2)
The same topic in other frameworks
From the topic crosswalk: the clauses filed under the same topics as this one. Mappings are illustrative, not a claim of conformity.
Human oversight
- EU AI Act Art. 14 Human oversight (core)
- ISO 42001 A.9 Use of AI systems (core)
- NIST AI RMF MANAGE 2.4 MANAGE 2.4: Mechanisms are in place and applied, and responsibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use (core)
- TC260 Framework 3.0 TC260 App. 2 II.3 Strengthen human approval (core)
- GDPR Art. 22 Automated individual decision-making, including profiling (core)
- NIST AI RMF MAP 3.5 MAP 3.5: Processes for human oversight are defined, assessed, and documented in accordance with organizational policies from the GOVERN function (core)
- CSA AICM GRC-15 Human supervision (core)
- Korea AI Act Art. 34(1)(4) Human management and supervision (core)
- UK DUAA UK GDPR Art. 22C Safeguards for automated decision-making (core)
- UK ATRS ATRS 2.3.2 Human review (core)
- Singapore Agentic Agentic 2.2.2 Design for meaningful human oversight (core)
- GAO AI Accountability 3.9 Human supervision: define and develop procedures for human supervision of the AI system (core)
- EU AI Act Art. 26 Obligations of deployers of high-risk AI systems
- NIST AI RMF GOVERN 3.2 GOVERN 3.2: Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight of AI systems
- China Algo. Rec. AlgoRec Art. 17 User option to switch off
- China GenAI Measures GenAI Art. 10 User guidance and protection
- EU AI Act Art. 14(4)(b) Awareness of automation bias
- CoE Convention CoE Art. 8 Transparency and oversight
- OECD AI Principles OECD 1.2(b) Human agency and oversight safeguards
Robustness, security and evaluations
- EU AI Act Art. 15 Accuracy, robustness and cybersecurity (core)
- EU AI Act Art. 55 Obligations for providers of general-purpose AI models with systemic risk (core)
- ISO 42001 A.6 AI system life cycle (core)
- NIST AI RMF MEASURE 2 MEASURE 2: AI systems are evaluated for trustworthy characteristics (core)
- TC260 Framework 3.0 TC260 3 Technological countermeasures (core)
- TC260 Framework 3.0 TC260 App. 2 II.6 Sandbox validation and red teaming (core)
- China Deep Synthesis DeepSyn Art. 15 Technology management and algorithm verification (core)
- China Deep Synthesis DeepSyn Art. 20 Security assessment of new products (core)
- GB/T 45654 GB/T 45654 Security assessment Security-assessment requirements for generative AI services (core) (clause not verified)
- GPAI Code Safety 3.2 Measure 3.2: Model evaluations (core)
- NIST AI RMF MEASURE 2.7 MEASURE 2.7: AI system security and resilience as identified in the MAP function are evaluated and documented (core)
- CSA AICM MDS-06 Adversarial Attack Analysis (core)
- CSA AICM MDS-07 Robustness against Adversarial Attack / Model Hardening (core)
- Singapore GenAI GenAI 5 Testing and Assurance (core)
- Singapore GenAI GenAI 6 Security (core)
- Singapore Agentic Agentic 2.3.2 Before deploying, test agents (core)
- CoE Convention CoE Art. 16(2)(g) Testing before first use and when significantly modified (core)
- OECD AI Principles OECD 1.4 Robustness, security and safety (core)
- G7 Code G7 Action 1 Identify, evaluate and mitigate risks across the lifecycle, including testing (core)
- GAO AI Accountability 3.7 Assessment: assess performance against defined metrics to ensure the AI system functions as intended and is sufficiently robust (core)
- EU AI Act Art. 60 Testing of high-risk AI systems in real-world conditions outside AI regulatory sandboxes
- ISO 42001 9.1 Monitoring, measurement, analysis and evaluation
- TC260 Framework 3.0 TC260 5.3.14 Resilience
- China GenAI Measures GenAI Art. 17 Security assessment
- EU AI Act Art. 15(3) Declared accuracy levels and metrics
- EU AI Act Art. 9 Risk management system
- EU AI Act Art. 42(3) Presumption of conformity for cybersecurity (Cyber Resilience Act)
- GPAI Code Safety C6 Commitment 6: Security mitigations
- GDPR Art. 32 Security of processing
- NIST AI RMF MEASURE 2.1 MEASURE 2.1: Test sets, metrics, and details about the tools used during TEVV are documented
- NIST AI RMF MEASURE 1 MEASURE 1: Appropriate methods and metrics are identified and applied
- CSA AICM AIS-05 Application Security Testing
- OWASP LLM LLM01:2026 Prompt Injection
- Korea AI Act Art. 32(1) Safety duties for AI above the compute threshold
- GAO AI Accountability 3.2 Metrics: define performance metrics that are precise, consistent, and reproducible
Supply chain and third parties
- EU AI Act Art. 25 Responsibilities along the AI value chain (core)
- ISO 42001 A.10 Third-party and customer relationships (core)
- NIST AI RMF GOVERN 6 GOVERN 6: Policies and procedures are in place to address AI risks and benefits arising from third-party software and data and other supply chain issues (core)
- NIST AI RMF MAP 4 MAP 4: Risks and benefits are mapped for all AI system components including third-party software and data (core)
- NIST AI RMF MANAGE 3 MANAGE 3: AI risks and benefits from third-party entities are managed (core)
- TC260 Framework 3.0 TC260 App. 2 II.4 Supply chain and tool management (core)
- EU AI Act Art. 25(4) Written agreement with third-party suppliers (core)
- GDPR Art. 28 Processor (core)
- NIST AI RMF MANAGE 3.1 MANAGE 3.1: AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented (core)
- CSA AICM STA-10 Supply Chain Risk Management (core)
- CSA AICM STA-09 Service Bill of Material (BOM) (core)
- OWASP LLM LLM04:2026 Supply Chain (core)
- EU AI Act Art. 26 Obligations of deployers of high-risk AI systems
- TC260 Framework 3.0 TC260 4.4.4 Open-source ecosystem
- China GenAI Measures GenAI Art. 7 Lawful data and model sources
- China Deep Synthesis DeepSyn Art. 14 Providers and technical supporters
- EU AI Act Art. 22 Authorised representatives of providers of high-risk AI systems
- EU AI Act Art. 23 Obligations of importers
- EU AI Act Art. 24 Obligations of distributors
- EU AI Act Art. 54 Authorised representatives of providers of general-purpose AI models
- GPAI Code Transparency 1.2 Providing relevant information
- GDPR Arts. 44–46 Transfers to third countries
- NIST AI RMF GOVERN 6.2 GOVERN 6.2: Contingency processes are in place to handle failures or incidents in third-party data or AI systems deemed to be high-risk
- UK ATRS ATRS 2.1.4 Third party involvement
- G7 Code G7 Action 11 Implement data input measures and protect personal data and intellectual property
- GAO AI Accountability 2.6 Dependency: assess interconnectivities and dependencies of data streams that operationalize the AI system
Agent identity and autonomy
- CSA AICM IAM-18 Agent Access Restriction (core)
- CSA AICM AIS-11 Agents Security Boundaries (core)
- OWASP LLM LLM03:2026 Excessive Agency (core)
- Singapore Agentic Agentic 2.1.2 Bound risks through design by defining agents limits and permissions (core)
- TC260 Framework 3.0 TC260 App. 2 II.2 Identity and access management (core)
- EU AI Act Art. 14 Human oversight
- NIST AI RMF GOVERN 3.2 GOVERN 3.2: Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight of AI systems
- CSA AICM IAM-12 Unique Identities
- Singapore Agentic Agentic 2.2.2 Design for meaningful human oversight
- TC260 Framework 3.0 TC260 App. 2 II.3 Strengthen human approval
Open controls that evidence it
Draft controls in the open control profiles that map to this row: each states a requirement and the evidence it must leave behind.
-
AIGE-CTL-EVAL-001Authorization Boundary (Evaluation environment profile) -
AIGE-CTL-EVAL-002Network Egress Control (Evaluation environment profile) -
AIGE-CTL-EVAL-003Credential Isolation (Evaluation environment profile) -
AIGE-CTL-EVAL-004Tool and Action Mediation (Evaluation environment profile) -
AIGE-CTL-EVAL-006Stop Conditions (Evaluation environment profile) -
AIGE-CTL-AGENT-001Registry entry (Agent runtime profile) -
AIGE-CTL-AGENT-002Its own identity (Agent runtime profile) -
AIGE-CTL-AGENT-005Tool allow-list, deny by default (Agent runtime profile) -
AIGE-CTL-AGENT-007Runtime guardrail on every tool call (Agent runtime profile) -
AIGE-CTL-AGENT-008Execution budgets (Agent runtime profile) -
AIGE-CTL-AGENT-009Approval log, bound to the call (Agent runtime profile) -
AIGE-CTL-AGENT-010Per-agent circuit breaker (Agent runtime profile) -
AIGE-CTL-AGENT-011Drilled kill switch (Agent runtime profile) -
AIGE-CTL-AGENT-015Checkpoints on irreversible actions, failing closed (Agent runtime profile) -
AIGE-CTL-AGENT-016Code runs only in a sandbox (Agent runtime profile) -
AIGE-CTL-AGENT-017Output and egress filter (Agent runtime profile) -
AIGE-CTL-AGENT-019Local MCP servers sandboxed (Agent runtime profile) -
AIGE-CTL-AGENT-020MCP authorisation (spec 2026-07-28) (Agent runtime profile) -
AIGE-CTL-AGENT-021Replace long-lived secrets with short-lived credentials (Agent runtime profile) -
AIGE-CTL-AGENT-022Delegation, never impersonation (Agent runtime profile) -
AIGE-CTL-AGENT-023Memory write gate and rollback (Agent runtime profile) -
AIGE-CTL-AGENT-025Accountability across hops (Agent runtime profile) -
AIGE-CTL-AGENT-026Stopping third-party agents at your boundary (Agent runtime profile) -
AIGE-CTL-ASSURE-002Release Blocked Below the Eval Threshold (Assurance and evidence profile) -
AIGE-CTL-ASSURE-010Model Artefacts Signed at Build and Verified Before Load (Assurance and evidence profile)
Source
Chapter 08, section OWASP GenAI Security Project, checked against its sources on the review date above.
Machine-readable
- This obligation:
/api/v1/obligations/aige-obl-owasp-agentic.json - The register:
/api/v1/obligations.json· CSV - Schema and stability promise: open data and API
Cite this obligation
García Aibar, J. (2026). OWASP Top 10 for Agentic Applications 2026 (AIGE-OBL-OWASP-AGENTIC). In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0). https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/obligations/aige-obl-owasp-agentic. CC BY 4.0
BibTeX
@misc{aige2026obligation,
author = {Jorge García Aibar},
title = {{OWASP Top 10 for Agentic Applications 2026 (AIGE-OBL-OWASP-AGENTIC)}},
howpublished = {In AI Governance Engineering: The Thesis \& Body of Knowledge},
year = {2026},
version = {0.5.0},
doi = {10.5281/zenodo.22956197},
url = {https://aigovernanceengineer.com/obligations/aige-obl-owasp-agentic},
note = {Version 0.5.0}
}