Security1 publisher3 min readPublished
OWASP keeps prompt injection at number one and starts managing the blast radius
The 2026 GenAI LLM Top 10 leaves the first two entries untouched and promotes Excessive Agency three places. The list increasingly reads as guidance for containing damage rather than preventing it.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- OWASP has released the GenAI LLM Top 10 for 2026, updating one of the security community's key reference points for understanding risk in generative AI applications.
- Prompt Injection remains at LLM01 in the 2026 list, unchanged from 2025.
- Sensitive Information Disclosure also holds its position at LLM02.
- The biggest upward move in the 2026 list is Excessive Agency, moving from LLM06 to LLM03.
- Excessive Agency's move from LLM06 to LLM03 is a rise of three ranking positions.
Compiled by The WatchSomething wrong?How this is made
Why it matters
OWASP has published the GenAI LLM Top 10 for 2026, an update to one of the more widely used reference points for risk in generative AI applications [1]. Prompt Injection stays at LLM01 and Sensitive Information Disclosure stays at LLM02, while Excessive Agency climbs from LLM06 to LLM03 [2][3][4].
The stability at the top is the finding. Two of the three highest-ranked entries did not move at all, and the only change in the top three is an escalation rather than a demotion [18]. A risk list that reprints its number one unchanged is not describing progress; it is describing a problem the field has learned to live with. Check Point's reading of the list makes the reason explicit: AI applications ingest instructions and content from user prompts, retrieved documents, websites, emails, files, images, tool responses and connected services, and any of those can influence model behaviour [11]. On that account prompt injection is a foundational problem that controls have to address across the whole application, not at the model interface alone [12].
If the input side is unfixed, the remaining lever is consequence, and that is where the 2026 list moved. Excessive Agency's three-place rise is the biggest upward move on the chart [4][5]. Check Point attributes it to models now holding access to tools, APIs and business systems, which means more impact when a system is manipulated, drifts outside its intended scope, or simply decides wrongly [13]. OWASP runs a separate Top 10 for Agentic Applications covering planning, tool use, memory and autonomous execution, which extends the security model from what a model says to what a system can reach and is permitted to do [14]. Check Point points to its own earlier writeup on advanced agents finding unexpected routes to their objectives as evidence the distinction is already operational [17].
Two other changes point the same way. System Prompt Leakage has been replaced by the broader Hidden Context Exposure at LLM08 [6]; Check Point's argument is that a system prompt is one item among retrieved documents, memory, user information, application state, tool responses and internal instructions assembled during an interaction [15]. Misinformation rises two places from LLM09 to LLM07 [7][8]. The justification offered is downstream authority: an error matters more when the output feeds another application, drives a workflow, produces code or triggers an automated action, which puts the emphasis on validation and on what privileges downstream systems grant generated text [16]. Improper Output Handling stays on the list even as it slides down the ranking [9].
The rest of the stack is unchanged in a way that should temper the agent conversation. Supply Chain, Data and Model Poisoning, Vector and Embedding Weaknesses, and Unbounded Consumption all remain in the Top 10 [10]. None of those has been solved either; they have been crowded by newer failure modes.
For anyone doing the work, the practical read is that a control catalogue built around filtering the prompt window is now aimed at the wrong layer. The 2026 ordering rewards teams that can enumerate what each AI system is allowed to touch, what enters its context and from where, and what happens automatically when it produces an output. Watch whether the Agentic Applications list and the LLM list stay separate through the next revision, and whether Excessive Agency keeps climbing. If it reaches the top two next year, prompt injection will have stopped being the headline risk and started being the delivery mechanism.