OWASP GenAI Security Project
OWASP Agentic AI Top 10
Ranked list of the most critical security risks for agentic AI systems — combining LLMs with tools, memory, and autonomy.
4 mapped controls
- detective
AI-CTRL-003
Adversarial Robustness Testing for LLM Systems
Validate that production-bound LLM and agentic AI systems have been tested against direct prompt injection, indirect prompt injection, jailbreak, refusal evasion, and (where applicable) multi-modal adversarial inputs, with documented findings, remediation, and re-test cycles.
Security & Adversarial RobustnessISO 42001 NIST AI RMF EU AI Act OWASP LLM Top 10 +6v1.0.0 Reviewed 2026-05-01 - preventive
AI-CTRL-006
Human-in-the-Loop Design for High-Risk Decisions
Ensure that AI systems producing decisions with legal or similarly significant effects on individuals incorporate meaningful human oversight in the decision flow, with documented design, training, and audit trails.
Human OversightISO 42001 NIST AI RMF EU AI Act OWASP Agentic Top 10 +2v1.0.0 Reviewed 2026-05-01 - preventive
AI-CTRL-007
Output Filtering and Content Moderation
Apply layered output filtering and content moderation to LLM and generative AI systems to prevent disclosure of sensitive data, prohibited content, executable payloads, and policy-violating outputs.
Inference & OutputISO 42001 NIST AI RMF EU AI Act OWASP LLM Top 10 +6v1.0.0 Reviewed 2026-05-01 - preventive
AI-CTRL-019
Agentic AI Tool Authorization Boundaries
Restrict agentic AI systems to least-privilege tool authorizations; enforce approval boundaries for high-impact actions; log and review all tool invocations; and prevent privilege escalation across multi-step or multi-agent workflows.
Inference & OutputISO 42001 NIST AI RMF EU AI Act OWASP LLM Top 10 +5v1.0.0 Reviewed 2026-05-01