Guidelines  ·  2026-09-03

OWASP GenAI Security Project releases 2026 Top 10 for LLM Applications (flagship revision) and formally bundles Agent Control Standard

GuidelinesHigh impactGlobal
On 2026-09-02 (confirmed via json-ld datePublished on the genai.owasp.org blog and PRNewswire/StreetInsider wire distribution), the OWASP GenAI Security Project formally announced the 2026 edition of its flagship Top 10 for LLM Applications alongside the newly-absorbed Agent Control Standard (ACS runtime-control spec, whose donation to OWASP was separately reported ~Aug 26-29). The 2026 Top 10 edition incorporates updated risk rankings (Excessive Agency rose to #3), expanded threat coverage drawn from 'thousands of real-world AI security incidents,' and new cross-mappings to NIST, MITRE ATLAS, CWE, and OWASP's own Top 10 for Agentic Applications. Note: third-party trackers place the underlying document's initial resource-page posting around Aug 3-4, 2026; the Sept 2 date reflects the coordinated public/media launch (10,000+ downloads in 48 hours, 4 new sponsors, 30,000-member milestone) rather than a silent re-date, so it is included with this caveat for QA adjudication.
The OWASP LLM Top 10 is the most widely cited practitioner risk taxonomy for GenAI application security and is directly referenced by vendor tooling, red-team benchmarks, and enterprise AppSec programs. The 2026 revision's elevation of Excessive Agency and new cross-framework mappings (NIST/MITRE ATLAS/CWE) signal where practitioner controls should concentrate as agentic deployments scale, and the Agent Control Standard gives teams a vendor-neutral runtime enforcement spec to adopt.
Map existing LLM/agentic application security programs to the updated 2026 risk rankings; evaluate adoption of the Agent Control Standard for runtime policy enforcement; update AppSec testing and red-team scopes to reflect the new threat coverage and cross-framework mappings.
OWASP GenAI Security Project blogPRNewswire/StreetInsider press release
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →