An AI system that can take action needs a different security review from one that only produces text.
The OWASP GenAI Security Project announced updated resources Sept. 2, including its 2026 Top 10 for large language model applications and the addition of an Agent Control Standard.
OWASP said the updated risk guidance expands threat coverage and connections to established frameworks. The Agent Control Standard extends the project’s work toward enforcing controls while an agent operates. The organization also announced a framework crosswalk and expanded security solutions directory.
Together, the resources offer government development teams material for evaluating AI applications and the tools those applications can use. Their publication does not certify a particular product or establish that an agency implementation is secure.
A hypothetical procurement assistant illustrates the distinction. An agency might permit it to summarize a contract file and prepare a draft request for review. Giving the same assistant permission to change a vendor record or transmit a document would create a different set of decisions about access and approval.
The agency could test those boundaries deliberately. An evaluator might place misleading instructions inside a sample document and observe whether the assistant treats them as content to analyze or as instructions to follow. The desired result would be a system that stays within its approved task.
Another test could examine what happens when an authorized service is unavailable. The assistant should not gain broader access merely because its usual route fails. A reviewer would also need a record of the attempted action and its outcome.
These are illustrative evaluation scenarios, not findings about the new standard or a specific vendor’s software. They show how a general security framework can become a set of questions an agency can test.
OWASP’s update provides a starting point. The operational work is to define each agent’s authority, verify its limits and retain evidence that those limits hold when inputs or conditions change.
