The hardest AI security problems now live in what an agent is permitted to do

https://media.thenextweb.com/2026/08/eu-ai-act-enforcement-powers-inspect-fine-models.jpg

OWASP’s 2026 Top 10 for LLM applications moved excessive agency from sixth to third and dropped improper output handling from fifth to tenth, in the first edition weighted partly on incident data. Europe’s Cyber Resilience Act began requiring 24-hour vulnerability reports on 11 September, but it governs products rather than how an agent is deployed.

Excessive agency has moved from sixth place to third in OWASP’s 2026 top ten for LLM applications, and improper output handling has fallen from fifth to last. The hardest problems now sit outside the model, Steve Wilson argues.

Excessive agency is not about what a model says. It is about what it has been handed: the tools, credentials and scopes it can reach once it answers.

The 2026 edition was the first weighted partly on recorded incidents, 6,639 of them, counting for a quarter of the ranking against three quarters practitioner consensus.

Wilson co-led...

Copyright of this story solely belongs to thenextweb.com. To see the full text click HERE

Read more