OWASP Agentic Top 10
OWASP's peer-reviewed risk framework for autonomous and agentic AI applications, including systems that plan, use tools, hold memory, or coordinate multi-step workflows. It is guidance, not a certification.
2026 · OWASP GenAI Security Project · published 2025-12-09
00Answer
01Standing
Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.
OWASP Agentic Top 10 is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.
OWASP publishes the guide openly. Preserve the publication's attribution and license terms before reproducing or adapting its content in a product catalog.
02Registry record
- Registry status
- Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
- Control units
- 10Risk categories in the OWASP Top 10 for Agentic Applications 2026. These are risk categories, not certification controls, and are not ingested here.
- Control families
- Agent goal and context integrity · Tool and privilege misuse · Agentic supply chain · Memory and identity security · Human oversight and accountability
- Applies to
- AI · technology · SaaS · global
- Verification
- Primary — the issuing body's own page was read and states this version. checked 2026-08-30
03Version ledger
| 2026 | Current edition | 2025-12-09 |
06Related frameworks
Also applies to AI · The Cloud Security Alliance's vendor-neutral control framework for cloud-based AI systems, with implementation and auditing guidance plus the companion AI-CAIQ. It is a control catalog, not by itself a certification or STAR for AI designation.
- AIUC-1Q3 2026 (2026-07-15 release)
Also applies to AI · A quarterly updated standard and certification program for AI agents covering data and privacy, security, safety, reliability, accountability, and societal risk. Only AIUC can issue its certificate; registry inclusion makes no certification claim.
Also applies to AI · OWASP's current community-driven guide to the most critical security risks for applications powered by large language models. It is security guidance, not a compliance certification or organizational assurance report.
- CSA STARSTAR Level 1 and Level 2
Also applies to SaaS · The Cloud Security Alliance's cloud-assurance program and public registry. Level 1 is a CCM/CAIQ self-assessment; Level 2 is a third-party certification or attestation path. Tracking STAR does not place ControlFrame or any customer on the registry.