Security1 distinct publisher3 min readUpdated
The 2026 GenAI LLM Top 10 leaves the first two entries untouched and promotes Excessive Agency three places. The list increasingly reads as guidance for containing damage rather than preventing it.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
OWASP has published the GenAI LLM Top 10 for 2026, an update to one of the more widely used reference points for risk in generative AI applications [1]. Prompt Injection stays at LLM01 and Sensitive Information Disclosure stays at LLM02, while Excessive Agency climbs from LLM06 to LLM03 [2][3][4].
The stability at the top is the finding. Two of the three highest-ranked entries did not move at all, and the only change in the top three is an escalation rather than a demotion [18]. A risk list that reprints its number one unchanged is not describing progress; it is describing a problem the field has learned to live with. Check Point's reading of the list makes the reason explicit: AI applications ingest instructions and content from user prompts, retrieved documents, websites, emails, files, images, tool responses and connected services, and any of those can influence model behaviour [11]. On that account prompt injection is a foundational problem that controls have to address across the whole application, not at the model interface alone [12].
If the input side is unfixed, the remaining lever is consequence, and that is where the 2026 list moved. Excessive Agency's three-place rise is the biggest upward move on the chart [4][5]. Check Point attributes it to models now holding access to tools, APIs and business systems, which means more impact when a system is manipulated, drifts outside its intended scope, or simply decides wrongly [13]. OWASP runs a separate Top 10 for Agentic Applications covering planning, tool use, memory and autonomous execution, which extends the security model from what a model says to what a system can reach and is permitted to do [14]. Check Point points to its own earlier writeup on advanced agents finding unexpected routes to their objectives as evidence the distinction is already operational [17].
Two other changes point the same way. System Prompt Leakage has been replaced by the broader Hidden Context Exposure at LLM08 [6]; Check Point's argument is that a system prompt is one item among retrieved documents, memory, user information, application state, tool responses and internal instructions assembled during an interaction [15]. Misinformation rises two places from LLM09 to LLM07 [7][8]. The justification offered is downstream authority: an error matters more when the output feeds another application, drives a workflow, produces code or triggers an automated action, which puts the emphasis on validation and on what privileges downstream systems grant generated text [16]. Improper Output Handling stays on the list even as it slides down the ranking [9].
The rest of the stack is unchanged in a way that should temper the agent conversation. Supply Chain, Data and Model Poisoning, Vector and Embedding Weaknesses, and Unbounded Consumption all remain in the Top 10 [10]. None of those has been solved either; they have been crowded by newer failure modes.
For anyone doing the work, the practical read is that a control catalogue built around filtering the prompt window is now aimed at the wrong layer. The 2026 ordering rewards teams that can enumerate what each AI system is allowed to touch, what enters its context and from where, and what happens automatically when it produces an output. Watch whether the Agentic Applications list and the LLM list stay separate through the next revision, and whether Excessive Agency keeps climbing. If it reaches the top two next year, prompt injection will have stopped being the headline risk and started being the delivery mechanism.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
OWASP has released the GenAI LLM Top 10 for 2026, updating one of the security community's key reference points for understanding risk in generative AI applications.
Prompt Injection remains at LLM01 in the 2026 list, unchanged from 2025.
Sensitive Information Disclosure also holds its position at LLM02.
The biggest upward move in the 2026 list is Excessive Agency, moving from LLM06 to LLM03.
System Prompt Leakage has been replaced by the broader category Hidden Context Exposure at LLM08.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One interested publisher, no primary document
Everything in the cluster comes from a single vendor blog post. The factual core -- which entries moved and which held -- is specific and internally consistent, and its derived deltas (three places for Excessive Agency, two for Misinformation) check out, which lifts it above pure assertion. But the supplied material never links or quotes the OWASP list, omits the full ordering and any ranking methodology, and the interpretive and causal parts rest on the vendor's own reasoning plus an unnamed set of 'recent incidents' backed by its own earlier post.
Framework shipped; uptake evidence limited to its sponsor
There is a concrete artefact -- the 2026 list is out -- and one disclosed integration path, the publisher mapping its AI Security, agent security and red-teaming products to both the LLM and agentic Top 10s. Beyond that the supplied material offers no user counts, no organisations citing the 2026 revision, no compliance or procurement references, and no telemetry on the controls it recommends, so uptake of this revision cannot be sized.
Mostly sober description with a vendor tail
The descriptive spine is restrained: rank moves are reported without catastrophe framing, and the post explicitly warns against over-rotating to agents by noting supply chain, poisoning, vector and consumption risks all remain. The overstatement is modest and comes from two places -- causal certainty about why Excessive Agency rose, asserted without data, and the closing stretch that converts a taxonomy update into a case for the publisher's own product suite and red-teaming service.
Sponsor of the framework selling controls mapped to it
The sole publisher discloses that it sponsors the OWASP GenAI Security Project and that its AI Security, AI Agent Security, Workforce AI Security and AI Red Teaming lines are aligned to the LLM and agentic Top 10s. Every emphasis in the piece -- context boundaries, agent permissioning, output validation, adversarial testing -- maps onto something it sells, and it also cites its own research and its own prior post as corroboration. The disclosure is candid, which is why this is not scored higher, but the alignment between narrative and revenue is direct.
Low-controversy facts, single interested voice
Confidence is moderate-low. The rank changes are the kind of claim that would be easy to correct and are unlikely to be fabricated, and the derived deltas are self-checking, so the descriptive layer is probably reliable. But there is one source, it is an interested party, the primary OWASP document is absent from the cluster, the list is only partially enumerated, and no independent publisher corroborates any of it -- so the interpretive and causal layers should not be treated as settled.
security
Education's attack curve has a start date: 4,696 weekly hits per organisation in 20261 distinct publisher
build
A RAG pipeline injected itself: no attacker, just a book about LLMs in the index1 distinct publisher
invest
A Connecticut judge just priced prompt injection: no fine, no e-filing2 distinct publishers
product
Anthropic nudges its own agent-tampering risk from 'very low' to 'low'1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 17, 2026