Law / Frameworks / OWASP Agentic Top 10

OWASP Agentic Top 10 ASI04Agentic Supply Chain Vulnerabilities

Agentic Supply Chain Vulnerabilities arise when agents, tools, and related artefacts they work with are provided by third parties and may be malicious, compromised, or tampered with in transit. These can be both static and dynamical sourced components, including models and model weights, tools, plug-ins, datasets, other agents, agentic interfaces - MCP (Model Context Protocol), A2A (Agent2Agent) - agentic registries and related artifacts, or update channels. These dependencies may introduce unsafe code, hidden instructions, or deceptive behaviors into the agent’s execution chain.OWASP Top 10 for Agentic Applications, 2026 edition, December 2025, ASI04

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

The kinds of duty that reach it: security.

1
law
1
place
0
with court rulings behind them
1
not yet in force

The same ground elsewhere linked through the kinds of duty both controls are mapped from

A law in force is unmarked; the rest wear their state: not yet in force

AI risk obligations

1 law, 1 place
PlaceLawHow it reaches this control
European Union AI Act, Article 15 (accuracy, robustness and cybersecurity) from , in 14 months

Through its security duty. What it requires

Excerpts of the OWASP Top 10 for Agentic Applications, CC BY-SA 4.0. OWASP GenAI Security Project, Agentic Security Initiative, OWASP Top 10 for Agentic Applications 2026, https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/, licensed CC BY-SA 4.0 (https://creativecommons.org/licenses/by-sa/4.0/). Excerpted: only the first paragraph of each entry's Description is reproduced, verbatim. Every control of the framework.