What this means for your project
OWASP published an updated LLM Top 10 resource page in August 2026 and an Agent Control Standard (ACS) resource in September. When looking for current security guidance, distinguish these resources from the 2025 edition, which remains useful historical context.
If an agent calls tools and triggers external actions, check who grants permissions, where actions run, how they are recorded and who can stop them. These practical checks are our synthesis of the sources, not statistics on how often risks occur.
Walk through one task: are tool permissions bounded? Do authorization checks and business records sit outside the model? Can unknown outcomes be reconciled first? Has the receiving team tested pause and recovery? Before using ACS, check support in your framework and customer systems.
This page reviewed official resource pages, not every item in the new downloadable documents. Consult the originals for specific requirements. This synthesis does not establish changes in risk rankings or security certification.
Apply it in your project
Choose a task you are working on and check whether the approach applies. Record what to investigate, which step might change, who handles it and when to review. If you have no live project, use a practice case.