HOME / SERVICES / AI SECURITY
OWASP AGENTIC TOP 10
WE DID NOT COMPILE THIS LIST. THAT IS EXACTLY WHY WE TEST AGAINST IT.
On 9 December 2025 the OWASP Agentic Security Initiative published a Top 10 for Agentic Applications. It is worth understanding why that document matters before reading the risks themselves.
OWASP does not sell anything. The list was built by an open community of practitioners, it is vendor neutral, and no security firm controls it. That makes it the rarest thing in this industry: a standard you can hold your provider to, written by nobody with something to sell you.
We test against it for that reason. A standard we did not write is a standard you can audit us against.
What this page adds
The OWASP list describes the risks. It does not tell a South African organisation what each one means under POPIA, King V, Joint Standard 2 of 2024 or the Cybercrimes Act.
That mapping did not exist. Our team built it, one risk at a time, and it is free to read. Each page below sets out what the risk actually is, what it looks like in practice, what South African law requires of you, how we test for it, and the questions worth putting to your team before your next agent goes live.
Risk
What it is
Primary South African instrument
The agent is redirected by content it reads, not by a message anyone sent it
POPIA sections 19 and 22, Joint Standard 2
Permissions granted one tool at a time, attacked one chain at a time
Joint Standard 2, POPIA section 71, Cybercrimes Act section 2
Shared credentials and actions nobody can attribute
POPIA sections 19 to 22, King V accountability
The integration, the token and the third party your agent trusts by default
POPIA sections 20 and 21, Joint Standard 2 third-party equivalence
What the agent runs when the input was never meant to be code
Cybercrimes Act section 2, POPIA section 19
A false memory planted once, acted on for weeks
POPIA section 22 notification, Joint Standard 2 24 hour clock
What one agent will believe because another agent said it
POPIA section 71, King V human oversight
One wrong decision, propagated at machine speed
Joint Standard 2 simulated incidents, King V override
Your people trust the agent, and that trust is an attack surface
POPIA section 71, Cybercrimes Act section 2
The agents nobody registered, nobody owns and nobody is watching
King V acquisition and assurance, POPIA section 21
The regulatory picture, in short
South Africa has no dedicated AI legislation. The National AI Policy was gazetted in April 2026 and withdrawn on 26 April 2026 after fabricated citations were found in its reference list. A revised draft is targeted for January 2027.
The obligations that already apply did not wait for it.
King V
From financial years beginning on or after 1 January 2026. Governing body accountable for the acquisition, development, use and distribution of technology. Demonstrable accountability for decisions, actions, outputs and outcomes. Human oversight and override proportionate to risk. Periodic assurance.
Joint Standard 2 of 2024
In force since 1 June 2025 for banks, insurers, asset managers, retirement funds and credit rating agencies. Board ultimately accountable under a board-approved cyber risk charter. Documented evidence of control testing including simulated incidents. A maintained testing calendar. Third-party controls equivalent to your own. Material incidents notified to the FSCA or Prudential Authority potentially within 24 hours.
POPIA
Section 19 security safeguards. Sections 20 and 21 operator obligations, where an operator processing on your behalf does not transfer your liability. Section 22 notification to the Information Regulator and to affected data subjects. Section 71 restrictions on decisions based solely on automated processing.
Cybercrimes Act 19 of 2020, section 2, unlawful access.
On 24 November 2025 the SARB, FSCA and Prudential Authority published a joint report on AI adoption in South African financial institutions. It is not binding, but it signals the supervisory direction: explainability, model risk management, data governance and board-level oversight.
Two distinctions worth holding on to
Using AI to test is not the same as testing AI
Several offerings in this market use AI as the engine that performs a test against ordinary applications and networks. That is a different product from adversarial testing of your own AI agents. The naming collision is genuine and it causes real confusion in procurement.
The OWASP LLM Top 10 is not the OWASP Agentic Top 10
They are two documents covering different problems. The LLM list is about what a model outputs. The agentic list, published 9 December 2025, is about what an agent does once it can act: goal hijack, tool misuse, inter-agent communication, cascading failure, rogue agents. If your provider maps to the first, ask about the second.
FREQUENTLY ASKED QUESTIONS
FAQ
What is the OWASP Top 10 for Agentic Applications?
An independent, vendor-neutral list of the ten most significant security risks in AI agent systems, published on 9 December 2025 by the OWASP Agentic Security Initiative and built by an open community of practitioners. No security firm controls it, which is what makes it usable as a standard to hold a provider to.
Does South Africa have an AI law?
No. The National AI Policy was gazetted in April 2026 and withdrawn on 26 April 2026 after fabricated citations were found in its reference list, with a revised draft targeted for January 2027. Existing obligations still apply in full: King V from financial years beginning on or after 1 January 2026, Joint Standard 2 of 2024 in force since 1 June 2025, POPIA, and the Cybercrimes Act 19 of 2020.
Where should we start if we have agents in production?
With an inventory. Most organisations cannot name every agent running inside them, and every obligation above assumes you can. The AI Exposure Review produces that inventory in days, along with one live adversarial test so you can see what the risks look like in your own environment.
TAKE ACTION
CAN YOUR BUSINESS AFFORD TO BE HACKED?
Contact us for a no-obligation discussion about your AI roadmap.