Interactive crosswalk · OWASP GenAI
OWASP LLM & Agentic Top 10 Crosswalk
Every entry in the OWASP Top 10 for LLM Applications survived from 2025 into 2026, but eight moved position and one was renamed. Trace where each risk moved, what actually controls it, and which of the ten agentic risks it reaches.
OWASP LLM & Agentic Top 10 · 2025 to 2026
The codes stayed. The risks moved.
The OWASP Top 10 for LLM Applications ranks the risks that matter most when software calls a language model. All ten entries survived into 2026, but eight moved position and one was renamed, so a control mapped to a 2025 identifier may now point at the wrong risk.
Select an entry for detail
Select any entry for its definition, both positions, and what changed inside it.
OWASP publishes two lists: the LLM Top 10 for applications that call a model, and the Agentic Top 10 (ASI01 to ASI10) for models that can use tools, hold memory and act. A filled cell means the 2026 edition links that LLM risk to that agentic risk.
Select any row or column heading
Mapping data from Appendix A of the OWASP Top 10 for LLM Applications 2026. Definitions are ours. OWASP pairs each mapping with its own account of the relationship, which is in the source document.
Want the full breakdown?
The companion article walks through each move, the incidents behind the reordering, and what to update in your controls mapping.
Read the full breakdown on the blog →