Skip to content

Security1 publisher3 min readPublished

OWASP now names seventeen agentic threats, and the control unit is the whole run

Version 1.1 of the Agentic Security Initiative's guide enumerates T1 through T17, up from fifteen. Cite the version, and stop reviewing agents one tool call at a time.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying OWASP now names seventeen agentic threats, and the control unit is the whole run
Generated illustration

What happened

  • The OWASP Agentic Security Initiative's Agentic AI - Threats and Mitigations guide defines seventeen threats, T1 through T17, in version 1.1 (December 2025).
  • Earlier versions of the OWASP threats and mitigations guide listed fifteen threats, so the taxonomy version should be checked before citing it.
  • The threat count grew by two between the earlier fifteen-threat version and version 1.1.
  • The unit of analysis is the plan rather than the agent: each step's output becomes the next step's input, so the question worth asking is what the whole sequence may reach.
  • Individual calls look reasonable while the sequence does not.

Compiled by The WatchSomething wrong?How this is made

Why it matters

OWASP's Agentic Security Initiative now enumerates seventeen agentic threats, numbered T1 through T17, in version 1.1 of its Agentic AI - Threats and Mitigations guide, dated December 2025 [1]. That gives a review board something it did not have last year: a numbered list to argue against, instead of an improvised threat model assembled per project.

The version matters as much as the count. Earlier releases listed fifteen threats [2], so the taxonomy has grown by two [3], and an unversioned citation in a control standard or an audit finding is now ambiguous. Pin the version in the text.

The framing shift underneath the list is the more consequential part. In Orca Security's reading of the material, the unit of analysis is the plan rather than the agent, because each step's output becomes the next step's input, so the question worth asking is what the whole sequence may reach [4]. Individual calls look reasonable while the sequence does not [5]. Eight of the seventeen threats, on Orca's count, arise primarily from autonomous execution across steps, between agents, or where no human decides in real time [6] - just under half the taxonomy sitting in the gaps between calls rather than inside any one of them [7].

Five properties of autonomous execution drive this, and Orca is explicit that each is a design fact present before any attacker arrives [8]. There is the action gap: the system performs an act with an effect in the world, and un-performing an act is a separate project from correcting an answer [9]. There is the compounding plan, in which an error or an injected instruction travels forward under the system's own authority and no later step re-examines where the instruction came from [10]. There is the runtime trust boundary, since which tools and data sources are in scope gets decided during execution [11]. There is non-determinism, where identical inputs produce different plans, so testing one path says nothing about tomorrow's path [12]. And there is the absence of a decision-time human, which turns a person reading a screen into a rule that has to be written down [13].

OWASP's State of Agentic AI Security and Governance report puts the compliance consequence bluntly: pre-deployment certification "loses value the moment an agent begins, accumulates context, loads tools dynamically, or modifies its own configuration" [14]. The same report reduces the governance question to what an agent can do without a human confirming the action [15]. That is a harder question than most model risk registers are built to answer, because the agentic case breaks assumptions the human identity model depends on: bounded sessions, human-speed action, and recoverable intent [16].

The control set that follows from run-level analysis is unglamorous and mostly operational: reversibility-tiered approvals, blast-radius caps, budgets, egress boundaries, and a stop mechanism with a named owner [17]. None of that is novel security engineering. The novelty is that it has to bound a sequence whose shape is not known until it executes.

Two things to watch. First, taxonomy churn: fifteen to seventeen in one revision [1][2] means anyone hard-coding threat IDs into policy should expect to renumber. Second, whether certification regimes absorb the runtime point, because a pre-deployment sign-off that OWASP itself describes as losing value at first tool load [14] will not survive contact with an auditor who has read the report. Orca also says its platform maps the AI services, identities, keys, and sensitive data an agentic system can reach in a cloud environment without agents [18]; that is a vendor claim about a vendor product, and it is not what makes the taxonomy useful.

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories