Security1 distinct publisher3 min readUpdated
Version 1.1 of the Agentic Security Initiative's guide enumerates T1 through T17, up from fifteen. Cite the version, and stop reviewing agents one tool call at a time.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
OWASP's Agentic Security Initiative now enumerates seventeen agentic threats, numbered T1 through T17, in version 1.1 of its Agentic AI - Threats and Mitigations guide, dated December 2025 [1]. That gives a review board something it did not have last year: a numbered list to argue against, instead of an improvised threat model assembled per project.
The version matters as much as the count. Earlier releases listed fifteen threats [2], so the taxonomy has grown by two [3], and an unversioned citation in a control standard or an audit finding is now ambiguous. Pin the version in the text.
The framing shift underneath the list is the more consequential part. In Orca Security's reading of the material, the unit of analysis is the plan rather than the agent, because each step's output becomes the next step's input, so the question worth asking is what the whole sequence may reach [4]. Individual calls look reasonable while the sequence does not [5]. Eight of the seventeen threats, on Orca's count, arise primarily from autonomous execution across steps, between agents, or where no human decides in real time [6] - just under half the taxonomy sitting in the gaps between calls rather than inside any one of them [7].
Five properties of autonomous execution drive this, and Orca is explicit that each is a design fact present before any attacker arrives [8]. There is the action gap: the system performs an act with an effect in the world, and un-performing an act is a separate project from correcting an answer [9]. There is the compounding plan, in which an error or an injected instruction travels forward under the system's own authority and no later step re-examines where the instruction came from [10]. There is the runtime trust boundary, since which tools and data sources are in scope gets decided during execution [11]. There is non-determinism, where identical inputs produce different plans, so testing one path says nothing about tomorrow's path [12]. And there is the absence of a decision-time human, which turns a person reading a screen into a rule that has to be written down [13].
OWASP's State of Agentic AI Security and Governance report puts the compliance consequence bluntly: pre-deployment certification "loses value the moment an agent begins, accumulates context, loads tools dynamically, or modifies its own configuration" [14]. The same report reduces the governance question to what an agent can do without a human confirming the action [15]. That is a harder question than most model risk registers are built to answer, because the agentic case breaks assumptions the human identity model depends on: bounded sessions, human-speed action, and recoverable intent [16].
The control set that follows from run-level analysis is unglamorous and mostly operational: reversibility-tiered approvals, blast-radius caps, budgets, egress boundaries, and a stop mechanism with a named owner [17]. None of that is novel security engineering. The novelty is that it has to bound a sequence whose shape is not known until it executes.
Two things to watch. First, taxonomy churn: fifteen to seventeen in one revision [1][2] means anyone hard-coding threat IDs into policy should expect to renumber. Second, whether certification regimes absorb the runtime point, because a pre-deployment sign-off that OWASP itself describes as losing value at first tool load [14] will not survive contact with an auditor who has read the report. Orca also says its platform maps the AI services, identities, keys, and sensitive data an agentic system can reach in a cloud environment without agents [18]; that is a vendor claim about a vendor product, and it is not what makes the taxonomy useful.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
The OWASP Agentic Security Initiative's Agentic AI - Threats and Mitigations guide defines seventeen threats, T1 through T17, in version 1.1 (December 2025).
Earlier versions of the OWASP threats and mitigations guide listed fifteen threats, so the taxonomy version should be checked before citing it.
The unit of analysis is the plan rather than the agent: each step's output becomes the next step's input, so the question worth asking is what the whole sequence may reach.
Individual calls look reasonable while the sequence does not.
Eight of the seventeen threats primarily arise from autonomous execution across steps, between agents, or where no human makes decisions in real time.
Five structural properties of autonomous execution create the difficulty; each is a design fact present before any attacker arrives, and each forces a specific control.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Specific and internally consistent, but single-source and vendor-authored
The factual core is precise and checkable in principle: a named document, a version number, a month, a threat-count delta, and two direct quotations from a second OWASP report. Nothing is hedged into vagueness, and the article itself warns that the taxonomy version must be checked before citing. Against that, the entire cluster is one article from the vendor whose product is promoted at the end, the primary OWASP documents are not in the supplied material, the enumerated threat list is truncated mid-sentence in the supplied body, and the structural-properties and control-set sections are analytical framing rather than measured findings.
No usage or deployment evidence supplied
The supplied material documents a document version bump and nothing about uptake. There are no named organizations citing T1-T17, no deployments of reversibility-tiered approvals, blast-radius caps, or stop mechanisms, no customer counts for the vendor's mapping capability, and no benchmark or incident data. A taxonomy release is not adoption, so this dimension cannot be scored.
Slightly overstated: prescriptive control advice outruns the evidence for it
The taxonomy claims are stated conservatively and the article explicitly tells readers to verify the version, which pulls the gap toward zero. The overstatement sits elsewhere: a control program covering approvals, caps, budgets, egress boundaries, and a stop mechanism is asserted as what bounds a run without a single case of it being operated, the identity-model assertion is delivered as settled, and the closing vendor capability claim is presented on the vendor's own say-so alongside neutral standards content. Modestly positive rather than strongly so.
Vendor-published category education ending in a product claim
The article is published by a cloud security vendor on its own blog, defines a category in the sense that favors its offering, explicitly disambiguates away from the competing sense of 'agentic AI security platform', and closes with a statement that its product maps the AI services, identities, keys, and sensitive data an agentic system can reach - agentlessly, a positioning contrast against agent-based competitors. Internal links to other company guides reinforce the funnel. The incentive is clear and structural, though partly offset by accurate third-party attribution to OWASP and by the self-imposed caveat to check the taxonomy version.
Moderate-low: one interested publisher, verifiable spine, no corroboration
Confidence is limited by the single-source, single-publisher cluster and by the absence of the underlying OWASP documents from the supplied material. It is not lower because the load-bearing claims are unusually specific and quoted rather than paraphrased, the article self-flags version risk, and the analytical sections are clearly labeled as design reasoning. Adoption remains unscored, which further caps the ceiling.
invest
The card networks just picked the referee for agent checkout, and it looks like EMVCo2 distinct publishers
leadership
Anthropic's own telemetry: 93% of permission prompts approved. Budget for blast radius, not reviewers1 distinct publisher
product
APIs built for human judgment now answer to agents that have none1 distinct publisher
build
An AI reviewer called injectable SQL safe because it could not read the helper1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 14, 2026