
OWASP Top 10 Agentic Applications
About the event
The OWASP Top 10 for Agentic Applications 2026 is a globally peer-reviewed framework that identifies the most critical security risks facing autonomous and agentic AI systems. Developed through extensive collaboration with more than 100 industry experts, researchers, and practitioners, the list provides practical, actionable guidance to help organizations secure AI agents that plan, act, and make decisions across complex workflows.
Using an OWASP-centric Agentic Threat Emulator integrated with an Agentic SOC Range, we’ll demonstrate all ten risk categories: ASI01 — Agent Goal Hijack ASI02 — Tool Misuse & Exploitation ASI03 — Identity & Privilege Abuse ASI04 — Agentic Supply Chain Vulnerabilities ASI05 — Unexpected Code Execution ASI06 — Memory & Context Poisoning ASI07 — Insecure Inter-Agent Communication ASI08 — Cascading Failures ASI09 — Human-Agent Trust Exploitation ASI10 — Rogue Agents
For each scenario we’ll examine the vulnerable architecture, how the attack propagates through the agent workflow, what telemetry should be generated, and which engineering controls can stop it. We’ll work across: Agents LLM gateways RAG Memory MCP Tools Identity Policy Agent-to-Agent communication Human approvals.
The objective: understand how to build agentic systems that are observable, enforceable, and secure by design.
https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/
Presenter: Rod Soto




