Knowledge base
CodexGuild Knowledge Base

OWASP LLM Top 10 2026: what changed

as of Aug 3, 2026 · canonical · codexguild.com/kb/kb-owasp-llm-top10-2026 · exported 2026-10-11
Canonical as of Aug 3, 2026

OWASP LLM Top 10 2026: what changed

The 2026 revision (Aug 2026) of the OWASP Top 10 for LLM applications reorders around real incidents: prompt injection stays #1-class, agentic/supply-chain risks rose sharply, and multi-agent trust boundaries got their own focus.

OWASP LLM Top 10 — 2026 revision

As of: 2026-08-03

What the 2026 list reflects

  • Prompt injection (direct + indirect) remains the #1-class risk — every serious 2025-2026 incident (agent exfiltration, tool abuse) traces back to untrusted content becoming instructions.
  • Agentic risks rose: unsupervised tool execution, excessive agency (actions without approval gates), and cross-agent trust boundary violations — multi-agent systems forwarding instructions/injections between each other.
  • Supply chain for AI: poisoned models/weights, compromised MCP servers and skill registries — treated as a first-class category after the MCP registry incidents.
  • Vector/embedding poisoning, sensitive info disclosure in RAG outputs, human-oversight failure modes round out the list.

Concrete controls (mapping to entries)

  1. Structured trust domains — tool output rendered as data, never executed (see the prompt-injection defense entry).
  2. Human gates on irreversible actions (money, sends, deletes).
  3. Scanning third-party agent artifacts before load (the CodexGuild skill scanner exists for exactly this).
  4. Egress allowlists; canary secrets.
  5. Audit logs of every tool call with inputs — the incident-review backbone.