Interactive crosswalk · OWASP GenAI

OWASP LLM & Agentic Top 10 Crosswalk

Every entry in the OWASP Top 10 for LLM Applications survived from 2025 into 2026, but eight moved position and one was renamed. Trace where each risk moved, what actually controls it, and which of the ten agentic risks it reaches.

OWASP LLM & Agentic Top 10 · 2025 to 2026

The codes stayed. The risks moved.

The OWASP Top 10 for LLM Applications ranks the risks that matter most when software calls a language model. All ten entries survived into 2026, but eight moved position and one was renamed, so a control mapped to a 2025 identifier may now point at the wrong risk.

2025 2026
Rose Fell Held Renamed

Select an entry for detail

Select any entry for its definition, both positions, and what changed inside it.

Positions verified against the OWASP Top 10 for LLM Applications 2026, v1.0. Scenario and citation counts are ours, taken from each entry's Example Attack Scenarios block, counting distinct inline references.

OWASP publishes its own rank migration figure on page 6 of that PDF; this restates it in a form you can link to and check. The four movement groupings are ours, derived from the published positions.

Built by CyberDesserts. Not affiliated with OWASP.

Want the full breakdown?

The companion article walks through each move, the incidents behind the reordering, and what to update in your controls mapping.

Read the full breakdown on the blog →