A lot can change in AI in less than two years.
The new OWASP Top 10 for LLM Applications 2026 reveals something bigger than a reshuffling of AI security risks: It reflects how the AI attack surface is changing fundamentally.
As AI evolves from generating answers to accessing enterprise data, connecting to tools, and taking action, the risks accompanying these actions are also evolving. And within this dynamic landscape, one trend is becoming increasingly clear: Data is moving closer to the center of AI security, making the latter increasingly inseparable from data security.
When we looked at the OWASP Top 10 in late 2024, AI applications were very different. Since then, RAG, persistent memory, and agentic AI have transformed them from systems that primarily generated content into systems that retrieve enterprise data, maintain context, connect to tools, and take action. The latest OWASP rankings reflect that evolution.
Let's look at what changed between 2025 and 2026, and what that tells us about where AI security is heading.
What Changed Between 2025 and 2026?
While no new risks appear in the 2026 list, their order has changed. More importantly, however, the new list reflects how, as AI systems gain more access to enterprise data and exercise greater autonomy to act on it, the potential dangers of AI vulnerabilities are not only changing, but also growing.
| Rank | 2025 | 2026 | Change |
| 1 | Prompt Injection | Prompt Injection | No change |
| 2 | Sensitive Information Disclosure | Sensitive Information Disclosure | No change |
| 3 | Supply Chain | Excessive Agency | Moves up (from #6) |
| 4 | Data and Model Poisoning | Supply Chain | Moves down (from #3) |
| 5 | Improper Output Handling | Data and Model Poisoning | Moves down (from #4) |
| 6 | Excessive Agency | Unbounded Consumption | Moves up (from #10) |
| 7 | System Prompt Leakage | Misinformation | Moves up (from #9) |
| 8 | Vector and Embedding Weaknesses | Hidden Context Exposure | Moves down and is renamed/re-scoped (from #7) |
| 9 | Misinformation | Vector and Embedding Weaknesses | Moves down (from #8) |
| 10 | Unbounded Consumption | Improper Output Handling | Moves down (from #5) |
While the reshuffling of the list is, in itself, interesting, what’s behind the changes is far more significant.
Sensitive Information Disclosure is Still Near the Top
Despite the extraordinary changes in AI architecture, Sensitive Information Disclosure remains firmly at #2.
And that consistency matters. AI systems increasingly interact with confidential business information, customer records, intellectual property, source code, financial information, and regulated data. RAG applications take AI to the next level by deliberately connecting models to enterprise knowledge. And AI agents go a step further, accessing information across databases, SaaS applications, and other enterprise systems to complete tasks.
But as AI gains access to more enterprise data, a fundamental security question remains: What type of sensitive data can AI access, and can AI expose such data to an entity that shouldn't have it?
With Sensitive Information Disclosure still near the top of the OWASP list, it’s clear that protecting sensitive data isn't a secondary consideration in AI security; it remains one of its foundations.
Prompt Injection Is Still #1, but the Stakes Have Changed
Prompt Injection remains unchanged at #1. What happens after a successful injection, however, is becoming far more consequential.
A manipulated chatbot that generates only text has a limited blast radius. But a manipulated AI system that retrieves private documents, query databases, invoke tools, or communicate with external systems presents a very different, and more serious, security problem.
OWASP's 2026 guidance clarifies this risk. Many high-impact prompt injection incidents become severe, because the compromised model has access to private data, broad permissions, or capabilities, enabling it to act outside the chat interface. This is already becoming a practical enterprise concern as sensitive data moves through AI conversations and workflows, where prompt injection can intersect directly with data exposure, as we recently explored in our work on securing enterprise use of Claude.
Consider this scenario. An enterprise assistant retrieves customer information to help employees answer support questions, and then an attacker succeeds in indirectly injecting malicious instructions through the retrieved content.
If the AI has narrowly-scoped access, the impact may be limited. But if the agent operates with a privileged service identity that can reach thousands of customer records and communicate externally, the same prompt injection could become a path to large-scale data exposure.
The vulnerability is still Prompt Injection. The potential danger, however, is determined by the data and privileges behind it.
Excessive Agency’s Jump to #3 is Most Revealing
Perhaps the clearest evidence of how AI security is changing is Excessive Agency, which jumps from #6 in 2025 to #3 in 2026.
OWASP describes this as the most consequential movement in the new list, reflecting the growing deployment of agentic systems and the real-world impact when AI is given excessive functionality, permissions, or autonomy.
This represents an important evolution. AI is no longer simply answering questions about data; it is increasingly acting on that data.
An AI agent, for example, might search a document repository, update a customer record, query a database, send an email, modify a cloud resource, or trigger another application. To carry out those actions, however, agents require identities and permissions. And that's where the data-security implications become significant.
Imagine an AI agent designed to summarize documents for an employee. To perform that task, it only needs to read that employee’s files. But the agent can invoke tools that interact with the document repository, and those tools operate through a service account with access to every document and permission to modify or delete them. If the agent is manipulated into taking an unintended action, those excessive permissions dramatically increase the potential impact.
The problem isn't simply that the AI agent can act autonomously. It is the combination of that autonomy with overly broad access to enterprise data.
As agency increases, organizations need to answer a new set of data-security questions: What sensitive data can this agent reach? Which identity is it using? Are its permissions broader than what its task requires? Can it only read the data, or can it modify, delete, or move it?
The rise of Excessive Agency suggests that data access governance is becoming a fundamental component of AI security.
Data Poisoning Expands Beyond Training Data
While Data and Model Poisoning moves slightly down the list, from #4 to #5, the category’s scope expands significantly.
Earlier AI security discussions often focused on protecting training datasets from manipulation. Modern AI architectures, however, depend on far more than training data.
OWASP's 2026 guidance recognizes that poisoning can occur anywhere data is ingested, transformed, retrieved, or reused, including during pretraining, fine-tuning, embedding creation, RAG, and continuous learning.
That changes the data-security equation.
Consider a customer service AI that uses a RAG knowledge base to answer customer questions. An attacker who gains access to that knowledge base may not need to compromise the model at all: By inserting carefully crafted information into a trusted data source, the attacker can manipulate future responses. Or take the case of persistent AI memory. If an attacker can poison information that an agent stores and later trusts, the attack can persist beyond a single conversation.
These scenarios mean that AI security isn't only about keeping sensitive data confidential. It is increasingly about maintaining data integrity.
Organizations must not only protect data from unauthorized exposure, but also understand who can modify the data on which their AI systems depend, where that data originated, and whether it can still be trusted.
From System Prompt Leakage to Hidden Context Exposure
Another subtle but important change in the list is the evolution of System Prompt Leakage into the broader Hidden Context Exposure category.
This reflects how much information now sits behind a modern AI interaction. A system prompt may be just one piece of the context assembled before a model produces an answer. The model may also receive developer instructions, retrieved enterprise documents, policy information, user profiles, tool definitions, application configuration, and other operational context.
Since much of that information was never intended to be visible to the user, the basic security question expands from:
Can someone extract the system prompt?
to:
What sensitive information is being assembled inside the AI context, and what happens if it becomes accessible?
That distinction becomes especially important with RAG. Enterprise information may move – often dynamically and invisibly to the user – from a database, file store, or SaaS application into a vector database and then into a model's context.
Organizations, therefore, need visibility into not only where sensitive data resides, but also how it enters and moves through AI applications.
AI Is Changing What It Means to Secure Data
Taken individually, these OWASP changes address different vulnerabilities. Taken together, they reveal a broader shift.
AI systems are becoming increasingly connected to enterprise data. They retrieve it; they combine it with other context; they make decisions based on it; they modify it; and, increasingly, they carry out autonomous actions involving it.
This means the security questions surrounding AI are also changing.
Organizations need to understand:
- What data can AI access?
- How sensitive is that data?
- Who or what has access to it?
- Is that access appropriate?
- Can the data on which AI relies be trusted?
- How is sensitive data moving through AI applications and agents?
- What can an AI system do with that data once it has access?
The 2026 OWASP Top 10 doesn't turn AI application security into data security. Prompt injection, supply chain vulnerabilities, resource consumption, and output handling remain important problems in their own right.
But it does highlight something increasingly difficult to ignore: The more AI becomes connected to enterprise data, the more securing AI depends on securing the data around it.
Extending Data Security Visibility Into AI
This changing threat landscape is also why we're extending data security into AI environments with Cortex Data Security. The offering provides visibility into the AI pipelines that interact with enterprise data, including models, agents, endpoints, and the data flows between them. It helps security teams identify sensitive data exposure, poisoning risks and privacy violations across training, deployment, and inference, while understanding which human, non-human, and agent identities can access sensitive information.

As AI continues to evolve from generating content to retrieving data and taking action, that visibility will become increasingly important. Securing the data that powers AI is becoming an essential part of securing AI itself.
To learn more about Cortex Data Security, request a demo today.