Skip to content

Security1 publisher2 min readPublished

Excessive Agency climbs from sixth to third in OWASP's 2026 LLM Top 10

OWASP's August 3 edition added no categories and removed none, yet eight of the ten entries changed rank, with Unbounded Consumption up four places and Improper Output Handling down five. Prompt Injection still holds first.

The Watch · Security desk

Illustration accompanying Excessive Agency climbs from sixth to third in OWASP's 2026 LLM Top 10

What happened

  • The OWASP GenAI Security Project published the 2026 edition of its Top 10 for LLM Applications on August 3, 2026.
  • All ten categories survived, with nothing added and nothing dropped, but eight of the ten entries changed position.
  • Excessive Agency moved from LLM06 to LLM03, Unbounded Consumption from LLM10 to LLM06, and Misinformation from LLM09 to LLM07.
  • System Prompt Leakage was renamed Hidden Context Exposure and widened to cover everything an application places in front of the model without the user seeing it.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision A review scoped around prompt filtering now skips the third-ranked entry, because what LLM03 asks a team to cost out is tool scope, reachable systems, and how far one model decision travels before a human approves it.
  • cost Consumption abuse reaches the finance owner before it reaches the SOC, since the traffic leaves no sample to detonate and no indicator to match.
  • constraint Reprioritising agent authority controls competes for the same engineering hours as patch work that has a deadline, and the edition does not set one.

Excessive Agency at LLM03 is a permissions question. Imperva's post defines the category as what an application is allowed to do once a model is driving it: which tools it can call and which systems it can reach, and how far one decision can travel before a human sees it [12]. Neither Excessive Agency nor Unbounded Consumption is a property of the model, Imperva argues; both are properties of an application in production [22].

The rename covers more ground than its position suggests. Hidden Context Exposure takes in retrieved documents, tool definitions, prior turns held in memory, and configuration a developer assumed was private because no interface displayed it [15]. It is, Imperva wrote, "the most consequential edit in the document" [14]. A team that tested only for system prompt extraction was testing one input class out of four.

Excessive Agency gained three places and Unbounded Consumption four, seven between them, against the five that Improper Output Handling lost [20]. In Imperva's account of the fall, the risk did not stop happening: application security teams have spent twenty years rendering untrusted output safely, refusing to execute what came back from an untrusted source, and treating downstream consumers as a boundary [16]. Unbounded Consumption describes an application meeting traffic engineered to abuse it, and Imperva wrote that this produces "no malware and no traditional indicators, just an enormous bill" [13].

Two of the ten entries held position [19], and both sit at the top: Prompt Injection first, Sensitive Information Disclosure second [10]. So the order does not move prompt-level defence down the queue. The places the two climbers gained came out of entries a team closes before the first request is served. Supply Chain, Data and Model Poisoning, and Vector and Embedding Weaknesses each slipped one [11], and Imperva locates all three in procurement, in the training pipeline, and in how the knowledge base was assembled and secured [17].

Misinformation's two places fit the same reading [7]. In Imperva's framing, a model which invents a refund policy is a quality problem in a lab and a liability problem in production [21].

A ranking change hands an attacker nothing, but it tells a reviewer where to start, and the two promoted entries start at tool scope and at rate and spend limits. Imperva published this reading as the fourth post in a four-part series [18]. The OWASP GenAI Security Project's own rationale for the movements is not in that account.

What to watch

  • Whether OWASP publishes per-entry rationale or incident data behind the reordering, which would show if the movements came from production telemetry or from committee judgement.
  • Whether agent platform and gateway vendors remap their control documentation to the 2026 numbering, so that LLM03 in a compliance matrix means agency rather than supply chain.
  • A 2027 edition that adds or drops a category, which would say the threat surface moved.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories