OWASP’s GenAI Security Project published the 2026 Top 10 for LLM Applications, updating its guidance for securing AI applications and autonomous agents with a methodology that blends community input and real-world incident data. The project analyzed 7,714 AI-related security incidents, including 6,639 detailed enough for classification, making this the first edition shaped in part by observed incidents rather than practitioner consensus alone. Prompt Injection remained the top-ranked risk, Sensitive Information Disclosure stayed near the top, and Excessive Agency rose to third as agentic deployments showed growing operational risk.
The update also reshaped several categories to reflect how attacks and failures are evolving. OWASP renamed System Prompt Leakage to Hidden Context Exposure, expanded Prompt Injection to include cross-modal attacks, and broadened Data and Model Poisoning to cover fine-tuning subversion. Misinformation moved higher because incident data showed significant real-world harm, while Unbounded Consumption was highlighted as an emerging availability and cost risk. OWASP said organizations should build resilient architectures around fallible models, using containment, least agency, access control before retrieval, output validation, and supply-chain security, and mapped the risks to frameworks including MITRE ATLAS, MITRE ATT&CK, CWE, NIST AI 600-1, NIST AI RMF, and the CSA AI Controls Matrix.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
OWASP rolled out a new agentic AI security maturity framework in June 2026 to help organizations align deployed agentic systems with required governance. The framework was referenced alongside the 2026 LLM Top 10 update.
OWASP renamed System Prompt Leakage to Hidden Context Exposure and broadened it to cover non-user-visible contexts such as system instructions, RAG schemas, and hidden policy logic. It also expanded Prompt Injection to include cross-modal attacks and broadened Data and Model Poisoning to include fine-tuning subversion.
The 2026 edition became the first OWASP LLM Top 10 influenced by real-world incident data rather than practitioner consensus alone. OWASP weighted practitioner voting at about 75% and incident data at 25%, using 6,639 classifiable incidents from a larger dataset of 7,714 AI-related incidents.
OWASP's GenAI Security Project released the 2026 edition of its Top 10 for LLM Applications. The update kept Prompt Injection as the top risk and Sensitive Information Disclosure second while revising lower-ranked categories based on community input and incident data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
heise.de
Open sourcereversinglabs.com
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcehelpnetsecurity.com
Open sourceinfosecurity-magazine.com
Open sourcegenai.owasp.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.