OWASP · AI Security
The security community updated its list of the biggest risks in AI applications. Here is a plain-language guide to what moved, what was renamed, and the important new line between AI as a component and AI as an actor.
The big idea: two lists, meant to be paired.
The old #7 gets a clearer name. It is not just the system prompt that can leak — hidden tool rules, developer notes, and retrieved policies are all “hidden context” the app quietly relies on. Now #8, and framed around never treating secrecy as security.
As AI apps gain tools and autonomy, three risks climbed the list: Excessive Agency (#6 → #3), Unbounded Consumption (#10 → #6), and Misinformation (#9 → #7). These are the risks that bite hardest once an AI can act, not just answer.
Prompt Injection now covers what an AI reads, hears, sees, or remembers — not just typed text. Data & Model Poisoning absorbs fine-tuning subversion. Supply Chain, Improper Output Handling, and Vector & Embedding Weaknesses all widened too.
The 2026 document draws a clearer line. The LLM Top 10 covers risks when the model is a component inside an application. Once the model becomes an actor — with tools, memory across sessions, and downstream consequences — the risk moves to the OWASP Agentic Top 10. The two lists are meant to be paired, because neither covers that ground alone.
Robot Explains is an independent educational adaptation and is not official OWASP guidance. It is based on the OWASP Top 10 for LLM Applications by the OWASP GenAI Security Project.
The OWASP material is licensed under Creative Commons Attribution-ShareAlike 4.0 (CC BY-SA 4.0), and this adaptation is shared under the same license.