SHIM
Contact UsFeaturesPricing
How to Start
BlogAbout UsDocs
Playground
SHIM

The enterprise-grade AI Gateway for security-conscious teams. Protect your data, govern spend, and account for usage.

Read Documentation→

Product

  • Features
  • Security
  • Pricing
  • Docs

Company

  • About Us
  • Blog
  • Playground
  • Contact Us

© 2026 SHIM Inc. All rights reserved.

SecurityPrivacy PolicyTerms of Service
SHIM
Contact UsFeaturesPricing
How to Start
BlogAbout UsDocs
Playground
SHIM

The enterprise-grade AI Gateway for security-conscious teams. Protect your data, govern spend, and account for usage.

Read Documentation→

Product

  • Features
  • Security
  • Pricing
  • Docs

Company

  • About Us
  • Blog
  • Playground
  • Contact Us

© 2026 SHIM Inc. All rights reserved.

SecurityPrivacy PolicyTerms of Service
SHIM
Contact UsFeaturesPricing
How to Start
BlogAbout UsDocs
Playground
Back to Blog|Home
AI Security

OWASP Agentic AI Top 10: An Architecture Problem

The OWASP Top 10 for Agentic Applications maps ten risks that mostly cannot be fixed with prompt engineering. Here is how ASI01-ASI10 map to infrastructure-layer controls.

August 5, 20269 min read

OWASP now maintains two separate top-10 lists for AI. The GenAI LLM Top 10 covers risks in LLM applications that respond to prompts. The OWASP Top 10 for Agentic Applications targets a different threat surface: systems that plan, act, and make decisions across complex workflows.

The threat model changes because the attack surface changes. An LLM application receives a prompt and returns text. An agentic system receives a goal, selects tools, calls APIs, and executes multi-step plans with minimal human oversight. It is no longer just about what an agent can access, but how much freedom it has to act on that access without checking back with you.

The OWASP agentic AI list introduces a governing principle called Least Agency. Least Privilege limits what permissions an entity has statically. Least Agency adds a temporal and decision layer: agents cannot make high-impact decisions autonomously. The implication is structural. Autonomy is a feature that should be earned, not a default setting. You need an enforcement layer that can grant and revoke that autonomy in real time. Prompt engineering cannot do that.

ASI01 Through ASI10: The Full List

The OWASP Top 10 for Agentic Applications 2026 ranks risks from most critical to least:

RiskNameWhat It Means
ASI01Agent Goal HijackAn attacker tricks the agent into changing its main goal or following new, hidden instructions
ASI02Tool Misuse and ExploitationAn agent applies a legitimate tool in an unsafe or unintended way, leading to data exfiltration or workflow hijacking
ASI03Identity and Privilege AbuseAn agent borrows too much power or uses old credentials to perform actions it should not be allowed to do
ASI04Agentic Supply Chain VulnerabilitiesRisks from third-party agents, tools, or prompt templates that may be malicious or tampered with at runtime
ASI05Unexpected Code Execution (RCE)The agent generates and runs a command that lets an attacker take over the server or system
ASI06Memory and Context PoisoningBad data is planted in the agent's memory, causing it to make biased or unsafe decisions later on
ASI07Insecure Inter-Agent CommunicationExchanges between agents that lack proper authentication or integrity, allowing spoofing or message interception
ASI08Cascading FailuresA single fault propagates and amplifies across autonomous agent networks, leading to system-wide impact
ASI09Human-Agent Trust ExploitationExploiting the anthropomorphism and persuasive nature of agents to manipulate human users into unsafe actions
ASI10Rogue AgentsCompromised agents that deviate from their intended scope, acting harmfully or pursuing hidden, deceptive goals

Walk through that list and a pattern emerges. ASI06 and ASI09 touch the model layer (poisoned context, manipulated trust). The remaining eight are infrastructure problems. Prompt tuning will not prevent an agent from borrowing a user's session (ASI03), executing unsigned third-party code (ASI04), or propagating a fault across a multi-agent network (ASI08).

ASI01 and ASI02: Goal Hijack and Tool Misuse Require Intent Gates

The top two risks share a common failure mode. Agents process natural language. They cannot reliably distinguish system instructions from malicious payloads injected into tool outputs, retrieved documents, or user messages. Filtering prompts is insufficient because the attack surface extends to every input the agent consumes.

The mitigation is an Intent Gate: agents must not perform high-impact or irreversible actions (like moving money, deleting records, or changing system configs) without a secondary check. Consider what this means in practice. An agent should not transfer $100,000 on its own, should not delete entire databases on corrupt input, should not grant admin access without human review.

An Intent Gate cannot live inside the agent itself. A hijacked agent will bypass its own guardrails. The gate must sit in the infrastructure layer, between the agent and the tool it is trying to invoke.

One pattern that implements this is Asynchronous Authorization (CIBA), where the agent requests an action, sits in a "pending" state, and only proceeds after the human approves on their device. The agent never holds the approval power. The infrastructure does.

This is where an AI gateway earns its role. SHIM is an enterprise gateway for AI that eliminates redundant API calls, enforces GDPR compliance, and provides full visibility into AI traffic, with built-in PII redaction. That interception point, between your application and LLM providers, is exactly where intent validation and step-up authentication belong.

ASI03 and ASI07: Identity Abuse and Insecure Inter-Agent Communication

These two risks are inseparable. ASI03 targets single-agent identity: an agent borrows too much power or uses old credentials to act beyond its scope. ASI07 targets multi-agent identity: exchanges between agents that lack proper authentication or integrity, allowing spoofing or message interception.

Both are structural. Editing the agent's system prompt will not fix them.

The identity mitigation has three parts. First, agents need their own managed identity with restricted scopes instead of borrowing a user's session. Second, credentials should be task-scoped tokens: short-lived credentials issued for specific, time-limited tasks with minimal required permissions. Third, inter-agent traffic should use mutual TLS (mTLS), which requires both agent and service to cryptographically verify each other's identity.

Together, these create a defense-in-depth: authentication (mTLS) + authorization (task-scoped tokens) + observability (audit logging). All three are infrastructure-layer controls. They require a gateway or control plane that manages agent identities, issues scoped tokens, and terminates mTLS connections. For a deeper look at how these identity controls fit into the broader agent security picture, we covered the enforcement patterns in our agent security guide.

ASI04, ASI05, ASI08, ASI10: Supply Chain, RCE, Cascading Failures, Rogue Agents

These four risks span different attack surfaces but share a property: they are only detectable and containable at the control plane.

ASI04 (Supply Chain). Third-party agents, tools, or prompt templates may be malicious or tampered with at runtime. Runtime is the key word. Static dependency scanning catches known vulnerabilities at build time. It does not catch a tool that was safe yesterday and compromised today. Runtime verification requires a gateway that inspects tool calls as they happen.

ASI05 (RCE). An agent generates and runs a command that lets an attacker take over the server or system. Sandboxing code execution is an infrastructure decision. The agent does not sandbox itself.

ASI08 (Cascading Failures). A single fault propagates and amplifies across autonomous agent networks. Circuit breakers, rate limits, and blast-radius controls are network-level constructs. They belong in the infrastructure that manages agent communication.

ASI10 (Rogue Agents). Compromised agents deviate from their intended scope, acting harmfully or pursuing hidden, deceptive goals. Detecting rogue behavior requires watching traffic patterns over time. As Human Security observes, many of the risks in the OWASP Top 10 for Agentic Applications 2026 show up as autonomous traffic whose goals have been hijacked, whose tools are being misused, or whose behavior has drifted into "rogue" territory while still looking superficially legitimate. Static rules cannot catch that. A monitoring layer that establishes behavioral baselines across agent traffic is the detection mechanism.

Building these controls into each agent independently is impractical. Centralizing them at the gateway or control plane is the pattern that scales. Our guide to AI agent guardrails covers the enforcement mechanisms in more detail.

ASI06 and ASI09: The Two Risks Closest to the Model Layer

Two OWASP agentic AI risks sit closer to the model itself.

ASI06 (Memory and Context Poisoning).Bad data planted in the agent's memory causes it to make biased or unsafe decisions later on. This targets the retrieval layer: vector stores, conversation history, cached tool outputs. The mitigation is context integrity checks, validating the provenance and freshness of retrieved data before it enters the agent's context window.

ASI09 (Human-Agent Trust Exploitation). Exploiting the anthropomorphism and persuasive nature of agents to manipulate human users into unsafe actions. This is a design problem as much as a technical one. The mitigation is transparency: making it clear to users when they are interacting with an agent, what the agent can and cannot do, and when the agent is uncertain.

Both benefit from infrastructure support (output scanning can flag manipulation patterns, and context validation can happen at the gateway), but they also require application-level design decisions that sit outside the control plane.

What the OWASP Agentic Top 10 Requires from Your AI Infrastructure

The pattern across ASI01 through ASI10 is consistent. The majority of risks require an enforcement layer between agents and their environment. Map the risks to the infrastructure capabilities they demand:

CapabilityRisks AddressedWhat It Does
Intent gates and step-up authASI01, ASI02Blocks high-impact actions without human or policy approval
Managed agent identityASI03, ASI07Issues task-scoped tokens, enforces mTLS between agents
Runtime supply chain verificationASI04Validates tools and templates at invocation time
Sandboxed executionASI05Isolates code execution from host systems
Circuit breakers and rate limitsASI08Contains fault propagation across agent networks
Behavioral monitoringASI10Detects deviation from established agent baselines

Microsoft validated this architecture pattern when it published guidance on addressing ASI01 through ASI04 in the context of Copilot Studio. The mitigations are platform-level controls.

Implementing Least Agency means having task-scoped tokens, approval workflows for high-impact actions, and audit logging of all agent decisions for human review. That sentence describes a gateway. If your AI governance framework does not include an infrastructure layer that can enforce these controls across every agent in your stack, the OWASP agentic AI list is telling you to build one.

Back to all articlesGet Started Free
SHIM

The enterprise-grade AI Gateway for security-conscious teams. Protect your data, govern spend, and account for usage.

Read Documentation→

Product

  • Features
  • Security
  • Pricing
  • Docs

Company

  • About Us
  • Blog
  • Playground
  • Contact Us

© 2026 SHIM Inc. All rights reserved.

SecurityPrivacy PolicyTerms of Service