Akamai acquires LayerX, delivering end-to-end security and real-time AI usage control to any browser. Get details
Background

The OWASP Top 10 for LLM Applications 2026: From Model Risks to Agentic Security

August 14, 2026 by Gal Meiri

Share

Key Takeaways

The OWASP Top 10 for LLM Applications 2026 maintains core threats like Prompt Injection and Sensitive Information Disclosure while reordering priorities based on real-world incident data and production deployment trends.

As AI models move beyond generating text to executing multistep workflows, risks like LLM03: Excessive Agency and LLM08: Hidden Context Exposure have risen in prominence to reflect broader attack surfaces.

Attackers increasingly map system logic, tool schemas, and guardrail boundaries prior to executing an exploit — making early detection of probing behavior critical to stopping multistage attacks.

Akamai Firewall for AI provides inline runtime protection across user prompts and model responses, stopping threats all over the kill chain, starting from the reconnaissance phase before attackers can misuse tools or exfiltrate enterprise data.

The newly released OWASP Top 10 for LLM Applications 2026 represents more evolution than revolution. Most of the core risks remain familiar to organizations that are building and securing generative AI applications. The most meaningful changes are in how those risks are prioritized, framed, and connected to the way AI systems are now being deployed.

The 2026 edition largely preserves the existing risk landscape, while refining category definitions and reprioritizing the list to reflect how AI applications are evolving (Figure). 

The 2026 edition largely preserves the existing risk landscape, while refining category definitions and reprioritizing the list to reflect how AI applications are evolving (Figure).
How the OWASP Top 10 for LLM Applications has evolved from 2025 to 2026
The 2026 edition largely preserves the existing risk landscape, while refining category definitions and reprioritizing the list to reflect how AI applications are evolving (Figure).

Prompt Injection (with a wider definition of the attack surface) and Sensitive Information Disclosure remain in the first two places. 

The most notable changes are the increased emphasis on agentic systems and the expansion of System Prompt Leakage into the broader Hidden Context Exposure category. 

Overall, the 2026 edition feels more mature and more closely grounded in real-world activity. Its structure and ordering reflect incidents, attack patterns, and deployment trends that have emerged over the past two years.

From our perspective, the new ranking closely aligns with what we are seeing across the market and within production AI environments.

Agentic AI moves to the center

One of the clearest themes in the 2026 list is the growing importance of agentic AI.

AI applications are no longer limited to generating text. Modern AI models interact directly with enterprise systems. They can retrieve data, invoke tools via APIs, and execute high-impact business workflows. 

This shift is reflected especially in LLM03: Excessive Agency and LLM08: Hidden Context Exposure, both of which receive greater prominence in the 2026 edition.

  • LLM03 addresses the risks created when an AI system has excessive functionality, permissions, or autonomy. A manipulated or unreliable model becomes significantly more dangerous when it can access sensitive or private information, update records, execute workflows, or trigger external systems without sufficient segmentation.

  • LLM08 expands the previous focus on system prompt leakage. Hidden context may now include developer instructions, internal configurations, retrieved policies, application workflows, user roles, tool and function schemas, permission models, and other operational information assembled inside the model’s context window.

Together, these changes reflect the growing security impact of AI systems that can both access internal context and act on it. As AI applications gain deeper access to enterprise data, tools, and workflows, weaknesses that once affected only model output can increasingly translate into real actions and broader system-level impact.

Securing AI systems that can take action

The increased prominence of LLM03 also reflects a broader trend across the industry. More AI applications are being equipped with connected tools and the ability to invoke them dynamically according to user requests or model-generated decisions.

These capabilities allow AI systems to move beyond generating answers. They can retrieve information from connected systems, access enterprise data, update records, execute workflows, call external services, and perform actions on behalf of users.

This is clearly where the industry is heading, but it also creates a much broader attack surface. Security breaches now extend beyond misleading text outputs. Attackers can exploit authorized tools, bypass workflows, exfiltrate sensitive data, or trigger unauthorized actions. 

By examining interactions across users, models, tools, and connected systems, Akamai Firewall for AI helps organizations maintain visibility and control as AI applications gain more autonomy and operational capabilities.

LLM08 and the importance of AI reconnaissance

LLM08 is particularly notable because it formalizes a risk that we have already identified through our AI security research: AI reconnaissance.

Attackers do not always begin with an obvious request for sensitive data or with an immediate attempt to exploit a tool. Instead, they may first try to map the application:

  • What is the assistant capable of doing?

  • Does it use a knowledge base?

  • Which tools and integrations are available?

  • What permissions and roles exist?

  • Which requests will it refuse?

  • How are workflows and decisions structured?

Individually, these questions may appear harmless. Together, their answers can provide the intelligence needed to create a precise, application-specific attack (as we demonstrated in a previous blog post).

The Hidden Context Exposure category (LLM08) captures this risk through the disclosure of tool schemas, behavioral logic, permissions, roles, refusal mechanisms, and workflow rules. This information can then support more targeted prompt injection, unauthorized access, tool abuse, or malicious action chaining.

This closely matches what we observed in our research across more than 170 real-world AI assistants. An assistant may resist a direct request for sensitive information while still revealing details about its capabilities, operational boundaries, connected tools, or knowledge sources. That information can convert a generic attack into a highly targeted threat.

Protecting the beginning of the attack chain

We recognized early that protecting only against the final exploit leaves an important gap. By the time an attacker submits a highly targeted prompt injection or malicious tool request, they may already have gathered the context needed to bypass application-specific controls.

For this reason, Akamai Firewall for AI customers will soon have access to a dedicated and unique reconnaissance detector that is designed to identify probing behavior such as:

  • Capability and boundary discovery

  • Tool and function enumeration

  • Knowledge-base probing

  • Permission and role discovery

  • Attempts to reconstruct internal instructions or workflow logic

This will enable organizations to detect suspicious activity at the beginning of the attack chain, before the attacker progresses to prompt injection, unauthorized data access, workflow abuse, tool misuse, or malicious actions.

Firewall for AI operates inline with AI application traffic and evaluates both user prompts and model responses. Organizations can apply application-specific policies and choose whether detected activity should be monitored, modified, or denied, regardless of the underlying model provider or AI platform.

Providing a more realistic AI security model

The OWASP Top 10 for LLM Applications 2026 does not completely redefine AI security. Instead, it provides a more mature and evidence-based view of the risks already emerging in production.

Securing agentic AI requires visibility across the entire attack chain - from reconnaissance and context discovery to data exfiltration or unauthorized actions.

Firewall for AI is built for this reality. It provides runtime protection across interactions with AI applications, helping organizations identify and control threats as users interact with models, and as those models become connected to sensitive data, tools, and business workflows.

Firewall for AI protects a broad range of AI-specific risks, including prompt injection and jailbreak attempts, sensitive data exposure, reconnaissance activity, harmful or off-topic use, and emerging agentic threats. 

By applying security controls directly to AI traffic, organizations can detect suspicious behavior, enforce policies before risky interactions progress further, and gain visibility into how their AI applications are actually being used and attacked. 

This becomes increasingly important as AI systems evolve from standalone chat interfaces into applications that can retrieve internal information, maintain context, invoke tools, and perform actions on behalf of users. 

Additionally, Akamai offers comprehensive AI security solutions that help enterprises operate safely in an AI-powered environment and secures digital interactions, both inside and outside an organization. Some of the key AI security solutions include Akamai Guardicore Segmentation, Akamai Workforce Protector, and Akamai Application Protection Platform, among others.

Learn more

Talk to your Akamai representative today to learn more about Akamai’s AI security solutions. 

About the Author(s)

Gal Meiri

Gal Meiri

Gal Meiri is a Senior AI Security Research Manager at Akamai and leads a group of security researchers and data scientists focused on securing generative AI applications and agentic workflows. His research examines emerging threats across the AI attack surface, and his work spans offensive and defensive AI security by building protection capabilities for securing AI interactions at runtime. Gal is also a public speaker who presents the latest threat intelligence at leading security conferences and industry events.