TL;DR: OWASP’s 2026 Top 10 for Agentic Applications maps the highest-impact failure modes in agentic systems, including goal hijacking, tool misuse, identity and privilege abuse, memory poisoning, and rogue behaviour across autonomous workflows, according to Lasso Security. Traditional AppSec, DLP, and cloud controls were not designed for agents that plan, act, and mutate state at runtime.
Editorial analysis by NHI Mgmt Group, based on content published by Lasso Security: “OWASP Top 10 for Agentic Applications”.
Key questions
Q: What breaks when agentic systems inherit broad application credentials?
A: Broad credentials create a runtime delegation gap because the system can use the same access for multiple actions that were never individually approved.
A: Security teams should test the full kill chain, not just perimeter blocking.
Q: What are the signs that agent memory or context is being poisoned?
A: Look for repeated bad recommendations, sudden shifts in tool selection, inconsistent task memory, or outputs that reference instructions the operator never approved.
Practitioner guidance
- Map every agent to a named identity owner Assign a human owner to each agent, document the business task it is allowed to perform, and record the credentials, APIs, and external services it can reach.
- Separate agent credentials from human accounts Issue agent-specific credentials with narrowly scoped permissions and avoid letting agents inherit broad human access or shared service tokens.
- Constrain tool use to approved action paths Define which tools an agent may call for each workflow stage and validate that tool selection stays within that stage.
Bottom line: Agentic applications create a new control problem because they can plan, act, remember, and coordinate at runtime with delegated authority.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Agentic AI creates an identity problem before it creates an application problem. OWASP’s taxonomy matters because it shows that the dangerous part is not just model output, but runtime behaviour that can select tools, change plans, and act through inherited access. That makes agent governance an identity and privilege discipline, not a narrow AI safety topic. Practitioners should treat agentic systems as controlled identities with observable trust boundaries.
A few things that frame the scale:
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems, inappropriately sharing sensitive data, and revealing access credentials, according to AI Agents: The New Attack Surface report.
- 52% of companies can track and audit the data their AI agents access, which means 48% still lack basic visibility into what those systems are touching.
A question worth separating out:
Q: What should organisations do when an agent starts mutating state or rewriting memory?
A: They should treat the agent as potentially compromised and isolate the memory, retrieval, and tool paths that can propagate the bad state. The key is to stop persistence from becoming replayable behaviour across later sessions or other agents that trust the same context.
👉 Read our full editorial: OWASP top 10 for agentic applications exposes new control gaps
Agentic security breaks the assumption that access is static long enough to be governed after the fact: access review, recertification, and conventional entitlement controls were built for privileges that persist across time. When an agent can acquire, use, and mutate authority inside a single runtime session, the governance object changes from standing access to execution-time behaviour. The implication is that identity programmes must treat runtime decision paths as first-class control boundaries.
A few things that frame the scale:
- Only about one-third of approximately 500 organizations surveyed by McKinsey in 2026 report maturity level three or higher across agentic AI governance controls.
A question worth separating out:
Q: How should security teams govern Agent2Agent communication in production?
A: Treat every agent as a governed non-human identity, not just a service integration. Require ownership, scoped authentication, traceable task IDs, and lifecycle offboarding before the first production workflow goes live. If an agent can discover peers and request access at runtime, it belongs inside identity governance and audit processes.
👉 Read our full editorial: OWASP top 10 for agentic applications exposes new control gaps