Law / Frameworks / OWASP Agentic Top 10
OWASP Top 10 for Agentic Applications
Below are its 10 controls in the framework's own order, and under each one the laws we track that bear on it. Each mapping is our reading that a law bears on a control, never a finding that running the control meets the law.
Where the law lands in the framework
4of 10 controls have law200laws123places
Of these laws, 166 are in force, 30 not yet in force, 1 blocked by a court, and 3 proposed and not law.
- in force
- not yet in force
- blocked by a court
- proposed
- no law we track
Read through the kinds of duty each AI and scraping law we track carries, counting a kind of duty only where the law's own requirement lines, as read against the NIST AI Risk Management Framework, bear it out.
| Control | What it says | Laws, by state | Laws | Places | Not yet in force | Blocked | Proposed |
|---|---|---|---|---|---|---|---|
| ASI01 | Agent Goal Hijack 1 law, 1 not yet in force | 1 | 1 | 1 | 0 | 0 | |
| ASI02 | Tool Misuse and Exploitation no law we track | no law we track | |||||
| ASI03 | Identity and Privilege Abuse 130 laws, 4 not yet in force | 130 | 103 | 4 | 0 | 0 | |
| ASI04 | Agentic Supply Chain Vulnerabilities 1 law, 1 not yet in force | 1 | 1 | 1 | 0 | 0 | |
| ASI05 | Unexpected Code Execution (RCE) no law we track | no law we track | |||||
| ASI06 | Memory & Context Poisoning no law we track | no law we track | |||||
| ASI07 | Insecure Inter-Agent Communication no law we track | no law we track | |||||
| ASI08 | Cascading Failures no law we track | no law we track | |||||
| ASI09 | Human-Agent Trust Exploitation 70 laws, 26 not yet in force, 1 blocked, 3 proposed | 70 | 41 | 26 | 1 | 3 | |
| ASI10 | Rogue Agents no law we track | no law we track | |||||
Where the law and the framework part
6 of the 10 controls have no law we track under them.
Kinds of duty this framework has no control for: age verification, attribution, biometric, breach notice, consent, contract terms, data subject rights, disclosure, DPIA, licensing, prohibition, reporting, retention, TDM, transfer.
The framework's text
Excerpts of the OWASP Top 10 for Agentic Applications, CC BY-SA 4.0. OWASP GenAI Security Project, Agentic Security Initiative, OWASP Top 10 for Agentic Applications 2026, https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/, licensed CC BY-SA 4.0 (https://creativecommons.org/licenses/by-sa/4.0/). Excerpted: only the first paragraph of each entry's Description is reproduced, verbatim.
Read it from the publisher: genai.owasp.org