METAL for iPhone

Read AI news in the METAL app.

Download METAL and discover fresh AI stories every day.

Download on the App Store

For iPhone · Free download

Search for METAL AI Magazine in the App Store on your iPhone.

METAL

AI GlossaryOSafety and controversy

OWASP Agentic Top 10

A list of ten key risks to watch for when deploying AI agents that reason and act on their own

In plain words

The OWASP Agentic Top 10 is a list of ten risks that need to be watched carefully so that AI agents—programs that judge situations and take action on their own—can be used safely. OWASP, the nonprofit that has long maintained security checklists for building websites and apps, put together this new list for an era when AI now sends emails, deletes files, and even makes payments on people's behalf.

Think of it like a safety manual written in advance for the kinds of accidents that can happen when you hand a new employee a company card and the office keys all at once. The AI agent plays the role of that new employee, and the list spells out, item by item, situations such as the agent mistaking someone's fake instructions for a real boss's orders, holding onto more permissions than it needs for too long, or having its stored memory quietly tampered with.

It's less a finished answer than a draft that will keep being revised. It works as a reference map showing people who build or adopt agents what they need to check ahead of time.

Try it yourself

If you're using a coding agent or a work AI agent, try asking it questions like this: "Check whether this agent has broader permissions than it actually needs when accessing external tools or accounts." Or: "Look into whether this agent could mistake instructions embedded in data other than the user's own commands—like emails, documents, or web pages—for real commands and act on them." You can go through the list's risk items one by one and ask for a check on each.

See also

Stories using this term

Browse every entry