Last updated:
A formal taxonomy of the ten most critical security risks specific to autonomous AI agents and their application environments.
Released in December 2025, the Agentic Security Initiative (ASI) taxonomy identifies risks like Goal Hijacking (ASI01) and Cascading Failures (ASI08). It serves as the primary security benchmark for agentic AI governance, forcing developers to move from prompt safety to application-layer enforcement.
Real world example:
A security team uses the OWASP Agentic Top 10 to red-team their new customer-service agent, discovering a Tool Misuse vulnerability where the agent could be tricked into deleting database records.




