Skip to content

Agentic threats mapped to controls

Rows are the OWASP Top 10 for Agentic Applications (2026). Columns are the 12 categories. A filled cell means the category mitigates that threat; the number is how many vendors have it as their primary category. On each threat page, only vendors that publish their own mapping to this threat are listed.

  1. 1. Agent identity and credentials
  2. 2. Delegated and user-to-agent auth
  3. 3. Agent authorization and fine-grained policy
  4. 4. Agent discovery and AI posture
  5. 5. MCP and AI gateways
  6. 6. Runtime guardrails and AI firewalls
  7. 7. AI data security and DLP
  8. 8. Agent detection, response, and audit
  9. 9. Red teaming and evaluation
  10. 10. Model and agent supply chain
  11. 11. Workforce AI usage control
  12. 12. AI governance and GRC

Also tracked: OWASP LLM Top 10 (2025)