Skip to content
technologyingovernment.com
Menu
  • Home
  • Expert Insights
  • News
  • Advertise
  • About TIG
  • Contact
Menu

OWASP adds controls guidance for AI agents

Posted on September 10, 2026

An AI system that can take action needs a different security review from one that only produces text.

The OWASP GenAI Security Project announced updated resources Sept. 2, including its 2026 Top 10 for large language model applications and the addition of an Agent Control Standard.

OWASP said the updated risk guidance expands threat coverage and connections to established frameworks. The Agent Control Standard extends the project’s work toward enforcing controls while an agent operates. The organization also announced a framework crosswalk and expanded security solutions directory.

Together, the resources offer government development teams material for evaluating AI applications and the tools those applications can use. Their publication does not certify a particular product or establish that an agency implementation is secure.

A hypothetical procurement assistant illustrates the distinction. An agency might permit it to summarize a contract file and prepare a draft request for review. Giving the same assistant permission to change a vendor record or transmit a document would create a different set of decisions about access and approval.

The agency could test those boundaries deliberately. An evaluator might place misleading instructions inside a sample document and observe whether the assistant treats them as content to analyze or as instructions to follow. The desired result would be a system that stays within its approved task.

Another test could examine what happens when an authorized service is unavailable. The assistant should not gain broader access merely because its usual route fails. A reviewer would also need a record of the attempted action and its outcome.

These are illustrative evaluation scenarios, not findings about the new standard or a specific vendor’s software. They show how a general security framework can become a set of questions an agency can test.

OWASP’s update provides a starting point. The operational work is to define each agent’s authority, verify its limits and retain evidence that those limits hold when inputs or conditions change.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Lockheed Martin Rolls Out Germany’s First F-35A, Starting a Path to More Interoperable NATO Operations
  • Week in Review: Events Shaping Government Priorities and Spending
  • Innoviz LiDAR Receives Israeli Defense Recognition for Counter-Drone and Perimeter Security Uses
  • Cemtrex’s Vicon Receives Federal Surveillance Orders and Adds Faster Video Review Tools
  • Leonardo DRS Wins KDDX Electric-Propulsion Work to Support Advanced Naval Systems
  • Home
  • Expert Insights
  • News
  • Advertise
  • About TIG
  • Contact
©2026 technologyingovernment.com | Design: Newspaperly WordPress Theme