The idea in one minute#
Five public frameworks cover AI security, and they answer different questions. The OWASP Top 10 for LLM Applications and the OWASP Top 10 for Agentic Applications say what goes wrong most often. MITRE ATLAS says how attackers actually do it, technique by technique. NIST’s AI Risk Management Framework and its control overlays say how to run a programme. The EU AI Act says what the law requires. Use the first two as checklists, the third for red teaming and detection, the fourth for governance, and the fifth for obligations. None replaces a threat model of your own system.
Everything dated here was checked on 4 October 2026.
A picture#
flowchart TB
TM[":i-list-checks: <b>Your threat model</b><br/><small>specific to your system</small>"]
subgraph WHAT["What goes wrong"]
direction LR
O1[":owasp: <b>OWASP LLM Top 10</b><br/><small>2026 edition</small>"]
O2[":owasp: <b>OWASP Agentic Top 10</b><br/><small>ASI01 - ASI10</small>"]
end
subgraph HOW["How attackers do it"]
direction LR
AT[":mitre: <b>MITRE ATLAS</b><br/><small>tactics, techniques, case studies</small>"]
end
subgraph RUN["How to run the programme"]
direction LR
N1[":nist: <b>NIST AI RMF</b><br/><small>govern, map, measure, manage</small>"]
N2[":nist: <b>COSAiS overlays</b><br/><small>SP 800-53 for AI</small>"]
ISO[":i-scroll-text: <b>ISO/IEC 42001</b><br/><small>management system</small>"]
end
subgraph LAW["What is required"]
direction LR
EU[":i-scale: <b>EU AI Act</b>"]
end
O1 --> TM
O2 --> TM
AT --> TM
TM --> N1
N2 --> TM
EU --> N1
ISO --> N1
class TM compute
class O1,O2 warn
class AT io
class N1,N2,ISO queue
class EU memoryHow it really works#
OWASP Top 10 for LLM Applications — 2026 edition#
Published on 4 August 2026. No category was added or removed since 2025, but the ranking was rebuilt from incident data, and it shifted toward what agents made dangerous.
| # | Risk | In one line |
|---|---|---|
| 1 | Prompt Injection | Text that changes the model’s behaviour; now explicitly includes instructions hidden in images and audio |
| 2 | Sensitive Information Disclosure | The system reveals private data, secrets or proprietary content |
| 3 | Excessive Agency | The model has more tools, permissions or autonomy than its task needs — up from sixth place |
| 4 | Supply Chain | Compromised models, datasets, packages, tools |
| 5 | Data and Model Poisoning | Corrupted training, fine-tuning or retrieval data |
| 6 | Unbounded Consumption | Resource exhaustion, denial of wallet, model extraction by volume |
| 7 | Misinformation | Confident wrong output that people or systems act on |
| 8 | Hidden Context Exposure | Leakage of system prompts and other context the user was not meant to see — the renamed and widened “System Prompt Leakage” |
| 9 | Vector and Embedding Weaknesses | Attacks on retrieval: poisoned chunks, cross-tenant leaks, embedding inversion |
| 10 | Improper Output Handling | Model output passed unvalidated to a browser, shell, database or API |
The edition’s framing is the one this course adopts: assume the model will be fooled, and put the controls around it.
OWASP Top 10 for Agentic Applications#
Announced in December 2025 for systems where models plan, use tools, keep memory and work with other agents.
| ID | Risk | Primary defence | Covered in |
|---|---|---|---|
| ASI01 | Agent Goal Hijack | Treat all retrieved content as untrusted; constrain what the agent may pursue | Prompt Injection |
| ASI02 | Tool Misuse and Exploitation | Least-agency tool scoping; argument validation | Architectural Defenses |
| ASI03 | Identity and Privilege Abuse | Per-agent identity; short-lived scoped credentials | Identity and Authorization |
| ASI04 | Agentic Supply Chain Vulnerabilities | Signed components; AI bill of materials; provenance | MCP and Tool Security |
| ASI05 | Unexpected Code Execution | Sandboxed execution; deny-by-default egress | Sandboxing and Egress |
| ASI06 | Memory and Context Poisoning | Validated memory writes; provenance | Agent Threats |
| ASI07 | Insecure Inter-Agent Communication | Mutual authentication; signed messages | Identity and Authorization |
| ASI08 | Cascading Failures | Blast-radius isolation; circuit breakers; budgets | Agent Threats |
| ASI09 | Human-Agent Trust Exploitation | Meaningful confirmation for sensitive actions | Architectural Defenses |
| ASI10 | Rogue Agents | Behavioural monitoring; kill switches | Monitoring and Response |
Use both lists as coverage checks: for each item, your design should name the control or state why the risk does not apply.
MITRE ATLAS#
ATLAS is to AI what ATT&CK is to enterprise networks: a matrix of adversary tactics (the goal of a step — reconnaissance, initial access, persistence, exfiltration) and the techniques that achieve each, backed by real case studies. Its 2025 and 2026 updates added a substantial set of agent-specific techniques — context poisoning, tool-invocation abuse, harvesting credentials that were ingested into a retrieval store, and others — and most of the current matrix is now relevant to agentic systems.
Where it earns its place:
- Red teaming — a technique list is a test plan.
- Detection engineering — each technique suggests what a log should show.
- Incident write-ups — a shared vocabulary for what the attacker did, step by step.
NIST#
- AI Risk Management Framework (AI RMF) organises work into four functions: Govern (policies, roles, accountability), Map (context and risks), Measure (test and monitor), Manage (prioritise and respond). It is voluntary and widely used as the backbone of an AI governance programme; a Generative AI profile adds specifics.
- COSAiS — Control Overlays for Securing AI Systems — adapts the familiar SP 800-53 control catalogue to AI use cases, including single-agent and multi-agent systems. It is in development; the agent-specific overlays were not yet final at the time of checking.
If your organisation already runs on SP 800-53 or ISO 27001, these are how AI gets folded into the existing control set rather than treated as a separate universe. ISO/IEC 42001 plays the same role as a certifiable management-system standard.
The EU AI Act, by date#
The Act classifies systems by risk and applies obligations in stages. The schedule was amended by the “Digital Omnibus on AI”, on which the Council and Parliament reached provisional agreement in May 2026.
| Date | What applies |
|---|---|
| 2 February 2025 | Prohibited practices (Article 5); AI-literacy duties |
| 2 August 2025 | Obligations for providers of general-purpose AI models |
| 2 August 2026 | Transparency duties (Article 50), including labelling of AI-generated content |
| 2 December 2027 | High-risk obligations for standalone Annex III systems — deferred from August 2026 by the omnibus agreement |
| 2 August 2028 | High-risk obligations for AI embedded in regulated products (Annex I) — deferred from August 2027 |
Formal adoption of the omnibus was still pending when this was checked; confirm the dates before relying on them, and note that a deferral is not an exemption. For engineers, the high-risk requirements read like a security and quality checklist: risk management, data governance, logging, human oversight, accuracy, robustness and cybersecurity. Compliance and Regulation maps them to controls.
Which to reach for#
| You need to | Use |
|---|---|
| Check a design for common gaps | OWASP LLM Top 10 and Agentic Top 10 |
| Plan a red-team exercise | MITRE ATLAS techniques |
| Decide what to log and alert on | MITRE ATLAS, per technique |
| Stand up or audit an AI governance programme | NIST AI RMF; ISO/IEC 42001 |
| Fold AI into existing security controls | COSAiS overlays on SP 800-53 |
| Know your legal duties in the EU | The AI Act, by risk class and date |
| Find what is wrong with your system | Your own threat model |
Remember this#
- OWASP lists say what goes wrong; ATLAS says how; NIST and ISO say how to manage; the AI Act says what is required.
- In the 2026 LLM Top 10, Excessive Agency rose to third: agents are the growing risk.
- The Agentic Top 10 (ASI01–ASI10) is the checklist for anything with tools and memory.
- EU high-risk deadlines moved to December 2027 and August 2028; transparency duties did not move.
- Frameworks check coverage. They do not replace a threat model.
Try it#
- Take the Agentic Top 10 and, for a system you know, write one line per item: the control, or why it does not apply.
- Pick one ATLAS technique and describe the log entry that would reveal it.
- Decide which AI Act risk class a product of yours would fall into, and which date applies.
Check yourself#
- What changed between the 2025 and 2026 OWASP LLM lists, and what does the change signal?
- What is ATLAS for that a Top 10 list is not?
- Why can no framework substitute for a system-specific threat model?