YOU DO NOT COPY PROFESSIONALISM. YOU ALIGN WITH IT.
HOME / SERVICES / AI SECURITY / OWASP TOP 10

ASI08 - CASCADING FAILURES

At 06:40 a pricing feed returns a stale figure. Nothing alerts, because nothing failed. The enrichment agent accepts it, the exception agent clears it, and the customer communications agent has written to several thousand people before the first person reaches a desk. No attacker was involved at any point. This is ASI08 on the OWASP Top 10 for Agentic Applications, published 9 December 2025 by the OWASP Agentic Security Initiative. In regulated South African firms, cascading agent failure testing is now a Joint Standard 2 question rather than an engineering curiosity, because the standard asks for documented simulated incidents and almost nobody has simulated one against a chain of agents.

ONE AGENT IS WRONG. EVERY AGENT AFTER IT IS CERTAIN.

Service chain diagram showing failure propagating from an authentication service through six downstream services beside a 24-hour clock.
DEFINITION

WHAT THIS RISK ACTUALLY IS

ASI08 is the risk that one incorrect output becomes the trusted input of everything downstream. Agent estates are built as chains. Retrieval feeds reasoning. Reasoning feeds a tool call. The tool call writes to a system that another agent reads on a schedule, and that agent writes to a customer. Every handover is a trust boundary. Almost none of them were drawn deliberately, because nobody sat down and designed a boundary. They emerged as each team connected the next useful thing.

What separates ASI08 from the rest of the list is that it needs no attacker. Goal hijack needs someone to plant an instruction. Supply chain compromise needs someone to steal a token. ASI08 needs one agent to be wrong in a way the next agent trusts. Wrong is not exotic. A stale cache. An API that returned a partial result under load. A date parsed in the wrong format. A model that answered confidently rather than accurately.

The impact profile is identical to an attack, and so is the response. Same blast radius. Same regulatory clock. Same customer harm. Same board briefing. Containment, scope, notification, remediation, in that order. The distinction between “we were attacked” and “our own automation was wrong at speed” matters to almost nobody outside the building, and it does not appear anywhere in the notification obligations.

You will recognise your own estate in this. Reconciliation. Claims triage. Collections. Customer communications. Ticket routing. Report generation feeding a dashboard that feeds an executive pack. Procurement approvals. Anywhere one automated step consumes the output of another.

The speed is the part that catches experienced teams out. Human processes contain latency, and that latency was doing safety work nobody credited: the overnight batch, the second signature, the person who thought a number looked odd. Agents remove the latency deliberately, because removing it was the business case. What was removed with it was the window in which a human noticed.

Watch for circular dependencies as well. An agent that reads from a store it also writes to will re-consume its own error and treat it as corroboration.

DOCUMENTED CASE

WHAT IT LOOKS LIKE IN PRACTICE

There is documented precedent for agents producing confident, wrong output at volume. In November 2025 Anthropic published its analysis of GTG-1002, a state-sponsored group that manipulated an AI model into functioning as an autonomous cyber attack agent, executing 80 to 90% of tactical operations independently against roughly 30 entities. Anthropic also recorded that the model frequently overstated findings and occasionally fabricated data during those autonomous operations. That caveat is the point for ASI08. An agent operating at machine speed generates plausible errors as readily as it generates correct results, and the next agent in the chain has no way to tell the difference.

WHAT THIS MEANS UNDER SOUTH AFRICAN LAW

DISCOVERY

NEWORDER connects to CI/CD pipelines to automatically discover and inventory every homegrown AI application, and integrates directly with AWS Bedrock, Google Vertex AI, Salesforce, and other cloud and third-party platforms for visibility into AI agents. Each AI system is profiled across its model, system prompt, tools, guardrails, policies, and configurations, and the inventory stays current on every change. You cannot secure what you cannot see; discovery is the non-negotiable first step.

AI SECURITY POSTURE MANAGEMENT (AI-SPM)

NEWORDER conducts a static analysis of every application’s configuration, policy coverage, and third-party dependencies and identifies any policy gaps. In addition, it maps each agentic application to its coverage of major frameworks, including NIST, OWASP, and MITRE. This gives you a clear, measurable view of your AI security posture before a single adversarial test is run, turning assumptions into evidence and compliance into a continuous output rather than a periodic exercise.

AI RED TEAMING

NEWORDER’s automated AI red teaming covers the complete kill chain from reconnaissance to exploitation. It proactively discovers exploitable vulnerabilities through automated reconnaissance and adversarial testing purpose-built for agentic applications. Static attacks draw from a 300K+ payload library with 100% MITRE and OWASP LLM and Agentic Top 10 coverage, running comprehensive sweeps of known jailbreak patterns, content moderation bypasses, and obfuscation techniques. Dynamic attacks use multi-turn and continuous probing to test how an application holds up across extended adversarial sequences, not just a single interaction. High-agency attacks deploy extremely customised, bespoke attack techniques through probing tailored specifically to the intent and design of each application.

RUNTIME PROTECTION

NEWORDER offers policy enforcement and AI threat protection at the proxy, API, or AI Gateway layer. Protection adapts as the applications evolve and as new capabilities are added. When an attack hits production, whether a jailbreak, a prompt injection, or any other AI threat, it is blocked in real time and an immediate alert is sent with full context, including what happened, which application was targeted, what the impact is, and what to do next. Key performance metrics include 98.6% threat detection accuracy, 1.4% false positive rate, sub-200ms time to detect, sub-50ms real-time blocking, and immediate mean time to respond.

Joint Standard 2 of 2024

, in force 1 June 2025, applies to banks, insurers, asset managers, retirement funds and credit rating agencies. It requires documented evidence of control testing, including vulnerability scans, penetration tests and simulated incidents, together with a maintained testing calendar.

A vulnerability scan cannot see a chain of individually correct components producing a wrong outcome. A simulated incident run against the agent chain is what shows where it stops, and if that simulation is not on the calendar, the evidence does not exist.

The standard also makes the board ultimately accountable and requires a board-approved cyber risk charter. If the charter does not name who may halt an agent chain, accountability sits with the board on paper and with nobody at 07:05.

Material incidents must be notified to the FSCA or the Prudential Authority potentially within 24 hours. A cascade discovered at 09:15 leaves you a few hours to establish scope across every agent that touched the wrong value, using logs whose completeness you have never tested.

King V

, effective for financial years beginning on or after 1 January 2026, makes the governing body accountable for the effective, compliant and ethical acquisition, development, use and distribution of technology, with demonstrable accountability for decisions, actions, outputs and outcomes, human oversight and override mechanisms proportionate to risk, and periodic assurance.

An override mechanism that has never been exercised is a claim, not a mechanism. The board question is not whether a kill switch exists. It is who is permitted to pull it, and when last anyone pulled it in a rehearsal.

POPIA section 71

restricts decisions based solely on automated processing that have legal consequences for a person or substantially affect them. A chain in which no human makes a decision at any node is a solely automated decision, regardless of the human who reviews the report afterwards.

POPIA sections 19 to 22

cover security safeguards, operator obligations and notification. Notification of a compromise goes to the Information Regulator and to affected data subjects. Those sections do not ask whether an attacker was involved.

The SARB, FSCA and Prudential Authority joint report of 24 November 2025 signalled the supervisory direction: explainability, model risk management, data governance and board-level oversight. That direction lands on chains, not on single models.

South Africa has no dedicated AI legislation. The National AI Policy was gazetted in April 2026 and withdrawn on 26 April 2026 after fabricated citations were found in its reference list, with a revised draft targeted for January 2027. The absence of an AI act changes nothing. The instruments above already apply, and the withdrawn policy is itself a small demonstration of what happens when confident output moves through a chain unchecked.

QUESTIONS TO ASK BEFORE YOUR NEXT AGENT GOES LIVE

  • If this agent produces a wrong but plausible output, which systems and which other agents consume it, and how far does it travel before a human sees it?
  • Who, by name and role, is permitted to halt this chain in production, and has that person ever done it in a rehearsal?
  • Does halting the orchestrator halt the sub-agents, or do in-flight tool calls complete anyway?
  • Can we reconstruct, from logs alone, every record touched by a single wrong value in the past 24 hours?
  • Does any agent read from a store that it or a downstream agent also writes to?
  • Is a simulated incident against this agent chain on our testing calendar, with a date, an owner and a retained artefact?
FREQUENTLY ASKED QUESTIONS

FAQ

No. ASI08 requires one agent to be wrong in a way the next agent trusts. A stale cache, a partial API response or a confidently fabricated value is enough. The impact profile and the incident response are identical to an attack: containment, scope, notification and remediation. South African notification duties under POPIA sections 19 to 22 and Joint Standard 2 do not distinguish between malicious cause and automation error.

Joint Standard 2 of 2024, in force since 1 June 2025, requires documented evidence of control testing including vulnerability scans, penetration tests and simulated incidents, plus a maintained testing calendar. Scans and penetration tests examine components. A cascading failure is a property of the chain. The simulated incident is the control that exercises it, and the artefact from that simulation is what an examiner will ask to see.

The hub page, The OWASP Agentic Top 10 for South Africa, carries the full regulatory mapping table across all ten risks. Read ASI08 alongside ASI07 Insecure Inter-Agent Communication, which explains why the next agent believed the wrong value in the first place. The Agentic Red Team page sets out how we run this against production estates.

WHERE TO GO FROM HERE

TAKE ACTION

TEST IT BEFORE SOMEBODY ELSE DOES

Thirty minutes on your agent estate and what this risk looks like in your environment.