Security1 distinct publisher3 min readPublished
OWASP's refreshed list names hidden context exposure and vector weaknesses, maps all ten risks to nine external frameworks, and moves the identifiers that older policy documents cite.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
The mapping is the part that changes conversations with assessors. OWASP put the ten categories against nine external frameworks and taxonomies, MITRE ATLAS and ATT&CK included, explicitly so organisations can fold LLM risk into existing risk-management programmes [12]. That removes the escape hatch of arguing that AI systems sit outside the control framework. A questionnaire can now ask for evidence category by category, in vocabulary the GRC team already owns.
Two categories will produce the most awkward findings. Hidden context exposure covers system prompts, developer instructions, tool schemas and policy information handed to a model but never meant for users [7]. OWASP's advice here is unusually prescriptive: assume it will be discovered, keep credentials, tokens and other secrets out of it, and do not let it be the only control enforcing authorization or policy [8]. That is testable in an afternoon. Someone opens the prompt, looks for a token, then looks for the sentence that is doing the access control on its own.
The second is the retrieval layer. Weaknesses in the vectors and embeddings behind RAG, agent memory and semantic search let an attacker poison retrieval results, pull information out, or exploit data that was never properly separated [9]. OWASP's multi-tenant example is the one to sit with: an attacker may infer things about another customer's documents even where authentication controls are in place [10]. A failure that survives a correct authentication check is a failure your existing evidence does not speak to.
Supply chain has widened in the same direction. OWASP describes LLM supply chains as reaching past conventional software dependencies into third-party models, training data, adapters and model artifacts, any of which can be poisoned, tampered with or swapped for a malicious replacement, with breaches, biased output or outright failure as the result [6]. The companion explainer frames each of those as a trust boundary the organisation never reviewed but which still shapes production behaviour [19]. Dependency inventories built for packages do not enumerate a fine-tuning dataset or an adapter.
None of this closes with a filter. Prompt injection is not a parsing bug; it works because the model cannot separate instruction from data when both arrive as natural language, which makes sanitisation rules borrowed from structured query injection structurally insufficient [15]. So the compensating controls have to live elsewhere, which is why excessive agency matters more than its old position suggested: too much functionality, permission or autonomy, at exactly the moment agents are being wired into external tools, systems and data [5].
Then the bookkeeping problem. In the earlier breakdown still circulating in AppSec material, excessive agency is LLM08, sensitive information disclosure is LLM06, and insecure output handling is LLM02 [16]. In the 2026 ordering, excessive agency is third and sensitive information disclosure second [2], a jump of five and four places respectively [17][21]. Any runbook, exception register or contract clause that cites an LLM number rather than a category name is now pointing somewhere else.
Worth noting what the source actually ranks: the top three are ordered, and the other seven categories, among them unbounded consumption, misinformation and improper output handling, are listed without stated positions [3]. Ten in total [18]. Also worth noting how OWASP expects these to surface: poisoning that skews recommendations and business decisions, misinformation that feeds operational disruption and bad human calls [11]. Neither arrives as an alert.
Ranked by verification strength, evidence, and original report placement.
Prompt injection remains the No. 1 risk on the 2026 list, followed by sensitive information disclosure and excessive agency.
Excessive agency addresses risks created when AI systems receive more functionality, permissions or autonomy than necessary, concerns that have grown as organisations deploy agents capable of interacting with external tools, systems and data.
OWASP said LLM supply chains extend beyond conventional software dependencies to include third-party models, training data, adapters and model artifacts, which attackers could manipulate through poisoning, tampering or malicious replacements, potentially causing security breaches, biased outputs or system failures.
The explainer describes LLM05 supply chain vulnerabilities as expanding traditional dependency risk to third-party base models, plugins, fine-tuning datasets and vector store contents, each a trust boundary the organisation did not directly review but that influences model behaviour in production.
The OWASP GenAI Security Project released its 2026 Top 10 for Large Language Model Applications, updating guidance as AI systems become more autonomous, interconnected and embedded in enterprise workflows.
The remaining categories cover supply chain risks, data and model poisoning, unbounded consumption, misinformation, hidden context exposure, vector and embedding weaknesses, and improper output handling.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Primary document summarized, single outlet
The core factual claims trace to a named primary artifact (the OWASP 2026 Top 10, publicly linked), which is strong provenance for a taxonomy story. But the cluster contains only one publisher's reading of that artifact, no direct quotation of the document's own identifier scheme, and the headline renumbering claim is an inference drawn by combining a news summary with an explainer written against the previous edition.
Published; uptake unobserved
The only observable events are the publication itself and the shipped framework crosswalk. No source reports an organization, regulator, vendor or tool adopting the 2026 categories or identifiers, and the one downstream artifact in the cluster still teaches the earlier numbering, so measured adoption is limited to the release event.
Broadly aligned, mildly forward-leaning
Coverage is descriptive rather than promotional: rankings, category definitions and OWASP's own guidance are reported close to the source. The small positive gap comes from framing the renumbering as consequential for policy documents while the cluster never publishes the new identifiers or any evidence that organizations must re-baseline, and from the derived position deltas being presented as cleanly as the sourced facts.
Standards-body and trade-press promotion, no direct commercial pitch
OWASP has a structural interest in its taxonomy being embedded in enterprise risk programs, which the nine-framework crosswalk directly serves. The publisher is a security trade outlet whose explainer argues that SAST, DAST and WAF are structurally insufficient — a framing that favors AI-security tooling narratives. Offsetting this: no vendor, product, price or sponsorship is named anywhere in the cluster, and the guidance is free and openly published.
Moderate: good provenance, no independent corroboration
Confidence is held down by the single-publisher cluster and by the absence of the 2026 identifier codes, which leaves the story's comparative spine inferential. It is held up by the named primary document, the specificity of the reported guidance, and the fact that the two items are internally consistent on category substance even where they differ on numbering.
security
OWASP keeps prompt injection at number one and starts managing the blast radius1 distinct publisher
build
A RAG pipeline injected itself: no attacker, just a book about LLMs in the index1 distinct publisher
invest
A Connecticut judge just priced prompt injection: no fine, no e-filing2 distinct publishers
security
Agent Tesla v4 hides in emoji and never hits disk: an email-rule problem, not a new-malware one2 distinct publishers
Distinct publishers with included, body-backed reporting in this cluster.
2 articles · August 26, 2026