Agentic AI Security · 2025–2026 Edition

Autonomous agents execute.
What stops them from
executing the wrong thing?

The definitive governance handbook for CISOs, CTOs, and risk leaders. From prompt injection to rogue agents — every threat explained, every control mapped.

40+
In-depth pages
20
Mapped threats
50
Audit checklist items
100%
Vendor-neutral

Select your role

Tailored reading paths for each leadership function — jump directly to what matters most for your responsibility area.

OWASP LLM & Agentic Security Risk Matrix

All 20 canonical AI vulnerabilities — categorized by attack domain and severity. Click any entry to read the full breakdown.

LLM01🔴 Critical

Prompt Injection

Crafted inputs hijack model context to override instructions or trigger unintended actions.

LLM02🟠 High

Sensitive Info Disclosure

Unsanitized context outputs reveal private PII, credentials, or proprietary system prompts.

LLM03🟠 High

Supply Chain Vulnerabilities

Compromised third-party models, plugins, or dataset dependencies.

LLM04🟠 High

Data Poisoning

Tampered training or fine-tuning datasets creating malicious backdoors.

LLM05🔴 Critical

Improper Output Handling

Passing raw LLM output into command shells, browsers, or SQL engines.

LLM06🔴 Critical

Excessive Agency

Granting model agents broad privileges or destructive tool access.

LLM07🟡 Medium

System Prompt Leakage

Extracting operational system prompts, business rules, or secret keys.

LLM08🟠 High

Vector Weaknesses

Exploiting embedding stores, RAG retrieval context, and vector DBs.

LLM09🟡 Medium

Misinformation & Hallucination

Confidently false outputs causing operational or compliance damage.

LLM10🟠 High

Unbounded Consumption

Uncapped API calls leading to resource exhaustion or financial DoS.

ASI01🔴 Critical

Agent Goal Hijack

Attackers manipulate an agent's objectives via malicious prompts, content, or indirect injection.

ASI02🔴 Critical

Tool Misuse & Exploitation

Agents invoke tools or APIs in unintended, destructive, or unauthorized ways.

ASI03🟠 High

Identity & Privilege Abuse

Agents inherit or escalate excessive permissions to perform actions outside authorization boundaries.

ASI04🟠 High

Agentic Supply Chain

Vulnerabilities introduced through untrusted MCP servers, packages, skills, or model registries.

ASI05🔴 Critical

Unexpected Code Execution

Agents dynamically generate and execute system commands or python scripts without isolation.

ASI06🟠 High

Memory & Context Poisoning

Attackers manipulate agent long-term memory or RAG indexes to influence future decision-making.

ASI07🟠 High

Insecure Inter-Agent Comm.

Spoofing, interception, or manipulation of messages within multi-agent workflow systems.

ASI08🟠 High

Cascading Failures

Small errors in parsing or planning compound iteratively to cause catastrophic system actions.

ASI09🟡 Medium

Human-Agent Trust Exploitation

Attackers manipulate agent outputs to exploit human over-reliance, causing unsafe actions.

ASI10🟠 High

Rogue Agents

Compromised or unmanaged agents spawned unauthorized, creating botnets or stealth backdoors.

Full Guide Overview

[O]OWASP LLM Top 10

The official OWASP top 10 vulnerabilities for large language models — every one explained with interactive examples.

[A]Agentic AI Top 10

The 10 critical risks unique to autonomous agents — from memory poisoning to runaway action loops.

Ready to govern autonomous AI in your organization?

Start with foundations or run the 50-point readiness audit.