Skip to content
Securafy AI Lab by Securafy
AI Automation & Agents

The OWASP 2026 Update Signals a New Risk for Teams Building AI Agents

OWASP moved Excessive Agency from sixth place to third in its 2026 Top 10 for LLM Applications, and it did that because most real-world AI risk now comes from agents with tool access and credentials, not chatbots giving a wrong answer. If your team is building or approving AI agents, here is what changed and what to check before you hand one real access.

In this article

OWASP moved Excessive Agency from sixth place to third in its 2026 Top 10 for LLM Applications, and it did that because most real-world AI risk now comes from agents with tool access and credentials, not chatbots giving a wrong answer. If your team is building or approving AI agents, here is what changed and what to check before you hand one real access.

What changed in OWASP's 2026 Top 10 for LLM applications?

Eight of the ten ranked risks moved position and one was renamed when OWASP released the update on August 4, 2026 at Black Hat USA, according to Help Net Security's coverage of the release. Prompt Injection stayed at the top of the list and Sensitive Information Disclosure held second place, but Excessive Agency jumped from sixth to third, Prompt Leakage was renamed Hidden Context Exposure, and Output Handling dropped to tenth.

The ranking is not a popularity contest among security researchers. As an analysis of the update's methodology notes, community votes carried 75 percent of the weight this cycle, but the remaining 25 percent came from data on 6,639 real incidents pulled from public vulnerability databases and an AI harm database. Excessive Agency rose because it is now showing up in actual breach reports, not because it sounded scarier in a workshop.

Why does excessive agency matter more than prompt injection right now?

Prompt injection still matters, and it remains the top-ranked risk for good reason. But the reason Excessive Agency climbed four spots in one cycle is that the nature of workplace AI changed. A year ago, most people were still asking a chatbot a question and reading the answer. Today, that same person may have connected an AI agent to their calendar, their CRM, or a shared drive, and given it standing permission to act on their behalf.

That shift changes what a mistake costs. A chatbot that gives a wrong answer wastes a few minutes. An agent with write access to a customer record, a file share, or an email account can take an action that is hard to undo before anyone reviews it. OWASP's own framing captures this directly: the 2026 list represents a move from protecting the conversation to containing the consequences.

Think about the difference in stakes. A chatbot that hallucinates a fact gets corrected in the next message. An agent with a standing connection to your calendar, your CRM, or a shared drive can send the email, update the record, or move the file before a person ever sees what it did. OWASP's own researchers describe today's deployments as giving language models persistent memory, tool access, credentials, and connections to the systems where a company keeps its most valuable data. Once an agent can retrieve files, query a database, or send a message on its own, a wrong output is no longer just wrong. It is an action with consequences that someone has to unwind.

Who is actually building the AI agents at your company?

If you assume agent building is an IT or engineering task, the data says otherwise. A 2026 enterprise report covered by Security Magazine found that enterprise environments now average roughly one AI agent, live or in draft form, for every employee, with agent interactions growing 14 times over between January and June of 2026 alone. Of the agents in that dataset, 67 percent were built by people without an engineering background, working in sales, customer success, and operations roles, often faster than security teams could review what those agents were allowed to touch.

That same report found that 60 percent of agents given access beyond default settings were granted allow-all permissions instead of being scoped to the task at hand, and that 60 percent ended up with configured capabilities that exceeded what the builder originally intended. Nobody set out to create an over-permissioned agent. It happened because scoping access takes more skill and more time than clicking allow.

What does over-permissioned AI access look like in practice?

A separate survey of 400 security and IT leaders by Akeyless found that two out of three organizations using AI agents suspect those agents have already accessed data beyond their intended scope, and that 80 percent of organizations reported an AI agent taking an unintended action, including unauthorized system access or unplanned data sharing. Fewer than half of the organizations surveyed said they were fully confident their identity systems could manage AI agents the same way they manage human employees.

This is the practical meaning behind Excessive Agency as a risk category. It is not a hypothetical about a rogue AI. It is a meeting summarizer that was also given send access to email, or a scheduling agent that was connected to a shared drive it never needed to read. Most of these agents work exactly as intended most of the time, which is part of what makes the excess access easy to miss until something goes wrong.

How should your team evaluate an AI agent before granting it access?

Treat every new agent the way you would treat a new employee's access request, not the way you would treat installing an app. Before turning one loose on real systems, work through a short set of questions with whoever built it:

  • What specific task does this agent need to complete, and what is the smallest set of permissions that task requires?
  • Does the agent have its own scoped credential, or is it reusing a person's login because that was faster to set up?
  • Which of its actions are reversible, and which ones need a human checkpoint before they happen?
  • Who reviews what the agent actually did last week, and how would your team notice if it started doing something different?

Organizations that build these habits are not the ones with the strictest bans. They are the ones where the person setting up the agent knows enough to ask the right question before clicking allow. That is a skills gap, not a tooling gap, and it is exactly the gap a well-built AI security and governance certification is meant to close for the people actually building these tools day to day.

Notice what none of those four questions require. They do not require a security engineering background or a platform migration. They require the habit of pausing before a permission prompt and knowing what a scoped credential looks like versus a reused login. A sales operations lead who has been through that training will set up a lead-routing agent differently than one who has not, even when they are using the exact same platform with the exact same default settings.

Does banning AI tools actually reduce this risk?

No, and the data on this point is fairly consistent. Cisco's 2026 Data and Privacy Benchmark Study found that organizations moved decisively away from blanket bans on generative AI between 2025 and 2026, and Cisco's own analysis of the findings explains why: people use AI tools regardless of policy, and outright bans mostly push that use underground, where nobody can monitor or govern it. The approach gaining ground instead combines user training, technical safeguards on what data can enter a system, and governance built into the point of interaction rather than a blanket prohibition.

That finding lines up with how AI use is actually spreading. Microsoft's 2026 Work Trend Index found that 78 percent of people using AI at work are bringing their own tools rather than ones their employer selected, a pattern that holds across company sizes and generations. Employees are not waiting for a governance committee to catch up. A policy that only says no will be quietly ignored. A team that knows how to evaluate and scope an agent will make better decisions with or without someone watching.

Building the judgment before you need it

None of this requires your team to become security engineers. It requires enough shared literacy that whoever is closest to the agent, often someone in operations or customer success rather than IT, knows what question to ask before granting access to a calendar, a customer database, or a shared inbox. That is a teachable skill, and it is the specific gap AI University exists to close, which is why our approach to AI training treats secure, governed use as a core part of AI literacy rather than a separate track bolted on afterward.

If you are not sure where your own team stands, an honest starting point helps more than a new policy document. Our AI readiness assessment gives you a clear picture of where your team's AI use already outpaces its governance, so you know exactly which skills to build first instead of guessing.

Next step

OWASP's 2026 update is a signal, not a deadline. The teams that come out ahead will be the ones who close the skills gap before an over-permissioned agent forces the issue. If you want help figuring out where your team stands and what to train first, book a strategy call and we will walk through it together.

Rodney Hall
Rodney Hall

Rodney Hall is the President and COO of Securafy, with 2 decades of experience in IT service management and operations.

He writes about the less glamorous but essential side of IT: support systems, documentation, business continuity, recurring issues, downtime, and the processes that keep client environments running well. His perspective comes from years spent improving how service is delivered, how teams respond, and how small problems are prevented from becoming much larger ones.

Outside of work, Rodney enjoys home improvement projects, woodworking, and dirt bike riding. His personal mission mirrors Securafy’s: helping businesses stay secure, compliant, and ready for whatever comes next.

Writes about: Managed IT, IT operations, service delivery, business continuity, downtime prevention, support processes, operational risk

More from Rodney Hall

Learn AI by building with it

AI University helps teams move beyond AI curiosity through practical lessons, secure workflows, guided experiments, and real projects built for everyday business use.

Explore AI University

Stay current on practical business AI

Get practical updates on AI security, governance, tools, compliance, and implementation without the daily hype cycle.

Join the conversation

Have a question or a different take on this? Add it below.