Join our Newsletter — 33% off our NHI Course

OWASP AI red teaming landscape: what changes for IAM teams?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: OWASP’s Q2 2026 Agentic AI Red Teaming Landscape formalises a shift from static application security to continuous behavioural testing across planning, data adaptation, development, runtime, and governance, according to Lasso Security. The security model for AI systems now has to account for tool misuse, memory manipulation, and agent chains that act across trust boundaries, not just code flaws.

Editorial analysis by NHI Mgmt Group, based on content published by Lasso Security: “The OWASP AI Red Teaming Landscape: Why Securing AI Requires a New Security Stack”.

Key questions

Q: What breaks when agentic AI is governed like a normal application account?

A: Security controls break down because agentic systems do not behave like fixed-function applications.

Q: Why do excessive permissions create more risk in agentic AI systems?

A: Excessive permissions raise risk because agents can act autonomously, chain tool calls, and trigger downstream systems faster than a human can intervene.

Q: How do security teams know if agentic AI controls are failing?

A: The main signs are session drift, repeated retry loops, unauthorized tool calls, and behaviour that diverges from the documented task sequence.

Practitioner guidance

  • Test complete agent execution paths Build red-team scenarios around tool poisoning, cross-agent prompt injection and multi-turn manipulation so you can observe how agents behave when context changes over time.
  • Map delegated permissions to runtime actions Inventory which tools, APIs and data sources each agent can touch, then compare that to the actions the agent can trigger without human approval.
  • Add runtime policy enforcement at the execution layer Place inspection and blocking controls where agent actions are actually executed, so unsafe calls can be stopped before they complete.

Bottom line: Agentic AI creates security failure modes that emerge during execution, not only in code or model outputs.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 2 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21364
 

AI security has moved from output control to behavioural governance. The OWASP landscape captures a real shift: the risk is no longer only what the model says, but what the agent does when it can act across tools, memory, and workflows. That changes the identity question from prompt safety to execution-path assurance. Practitioners should treat agent behaviour as a governance object, not a secondary output problem.

A few things that frame the scale:

  • 98% of companies plan to deploy even more AI agents within the next 12 months, despite documented rogue behaviour in 80% of current deployments, according to AI Agents: The New Attack Surface report.
  • Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.

A question worth separating out:

Q: What is the difference between testing AI models and governing AI agents?

A: Model testing focuses on prompts, outputs, and adversarial inputs, while agent governance focuses on the full action path, including tool calls, trust boundaries, and downstream effects. In practice, agents need continuous oversight because they can act across systems. That makes governance a runtime discipline, not a one-time validation exercise.

👉 Read our full editorial: The OWASP AI red teaming landscape and the new security stack



   
ReplyQuote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21364
 

AI security has moved from output control to behavioural governance. The OWASP landscape captures a real shift: the risk is no longer only what the model says, but what the agent does when it can act across tools, memory, and workflows. That changes the identity question from prompt safety to execution-path assurance. Practitioners should treat agent behaviour as a governance object, not a secondary output problem.

A few things that frame the scale:

  • 98% of companies plan to deploy even more AI agents within the next 12 months, despite documented rogue behaviour in 80% of current deployments, according to AI Agents: The New Attack Surface report.
  • Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.

A question worth separating out:

Q: What is the difference between testing AI models and governing AI agents?

A: Model testing focuses on prompts, outputs, and adversarial inputs, while agent governance focuses on the full action path, including tool calls, trust boundaries, and downstream effects. In practice, agents need continuous oversight because they can act across systems. That makes governance a runtime discipline, not a one-time validation exercise.

👉 Read our full editorial: The OWASP AI red teaming landscape and the new security stack



   
ReplyQuote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21364
 

Behaviour, not code, is now the primary security boundary for agentic AI: OWASP’s landscape reflects a deeper shift than better testing guidance. The core risk is that agentic systems fail through execution, sequencing and tool use, not just malformed inputs or weak model responses. That means security teams must stop treating AI as a static application problem and start governing the runtime behaviour of systems that can act across trust boundaries.

A few things that frame the scale:

A question worth separating out:

Q: What governance model fits agentic AI better than traditional app security reviews?

A: A lifecycle model fits better because the risk evolves from planning through deployment and operation. Traditional reviews are too episodic for systems that change with data, tools and runtime decisions. The stronger model combines adversarial testing, live monitoring and governance evidence so security remains aligned with the system as it changes.

👉 Read our full editorial: The OWASP AI red teaming landscape and the new security stack


This post was modified 2 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.