For the first time, the OWASP Top 10 for LLM isn't based solely on what experts believe is dangerous — it's based on 6,639 real incidents. And what climbed fastest in the ranking says a lot about where the risk is actually moving.
The 2026 edition was built with hundreds of AI security experts, but for the first time community vote (75% of the weight) was combined with data from 6,639 real incidents pulled from public vulnerability databases and an AI harms database (the remaining 25% of the weight) — a methodological shift that anchors the ranking in what's actually happening, not just what seems dangerous in theory.
Prompt Injection and Sensitive Information Disclosure held the top two spots, unchanged from previous editions. But **Excessive Agency** — the risk of an agent having more authority than it actually needs for its task — jumped from sixth place in 2025 to third in 2026, pushing supply chain and training-data poisoning risks further down. It's the clearest evidence of the shifting focus: the risk is no longer just "the model says something bad," it's "the agent does something bad with real permissions."
The 2026 edition reframes the entire goal: "stop trying to build a model that can't be tricked. Build the system around it, so that when the model is tricked — and it will be — nothing important breaks." It's a significant philosophical shift: instead of chasing perfect prevention (impossible), the focus moves to limiting the blast radius when prevention fails — the same defense-in-depth principle already applied in traditional cybersecurity, now made explicit for LLMs.
The Top 10 isn't a compliance checklist — it's a threat-modeling prioritization guide. For every AI system in production, it's worth explicitly reviewing which controls exist against the top 3-4 risks on the list (prompt injection, sensitive information disclosure, excessive agency) before worrying about the rarer risks at the bottom — that's where most real incidents, according to the 2026 data itself, keep concentrating.
Carlos Montiel is an enterprise AI solutions architect. He implements LLMs, Agents, RAG, and orchestrators for companies across Guatemala and Latin America. Reach out for a consultation.
Contact Carlos Montiel