Law / Frameworks / OWASP Agentic Top 10
OWASP Agentic Top 10 ASI09Human-Agent Trust Exploitation
Intelligent agents can establish strong trust with human users through their natural language fluency, emotional intelligence, and perceived expertise, known as anthropomorphism. Adversaries or misaligned designs may exploit this trust to influence user decisions, extract sensitive information, or steer outcomes for malicious purposes. In agentic systems, this risk is amplified when humans over-rely on autonomous recommendations or unverifiable rationales, approving actions without independent validation. By leveraging authority bias and persuasive explainability, attackers can bypass oversight, leading to data breaches, financial losses, downstream and reputational harms.OWASP Top 10 for Agentic Applications, 2026 edition, December 2025, ASI09
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
The kinds of duty that reach it: content labelling, design code, governance.
- 70
- laws
- 41
- places
- 1
- with court rulings behind it
- 26
- not yet in force
- 1
- blocked by a court
- 3
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFGOVERN 1.1 Legal and regulatory requirements involving AI are understood, managed, and documented.
- NIST AI RMFGOVERN 1.4 The risk management process and its outcomes are established through transparent...
- NIST AI 600-1GAI-RISK-07 Human-AI Configuration
- NIST AI 600-1GAI-RISK-03 Dangerous, Violent, or Hateful Content
- OWASP LLM Top 10LLM03:2026 Excessive Agency
- MIT mitigations2.4 Content Safety Controls
- MIT mitigations4.6 User Rights & Recourse
- NIST Privacy FrameworkID.IM-P4 Data actions of the systems/products/services are inventoried.
- NIST Privacy FrameworkID.RA-P1 Contextual factors related to the systems/products/services and the data actions are...
- NIST CSF 2.0GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including...
- NIST CSF 2.0GV.RR-01 Organizational leadership is responsible and accountable for cybersecurity risk and...
A law in force is unmarked; the rest wear their state: not yet in force blocked by a court proposed
AI transparency
36 laws, 28 placesShow the other 26 laws
AI risk obligations
14 laws, 8 placesShow the other 4 laws
| Artificial Intelligence (Designation of the Information and Data Protection Commissioner for the purposes of Regulation (EU) 2024/1689) Regulations, 2025 (L.N. 227 of 2025) |
Through its governance duty. What it requires |
|
| Right to Compute Act (SB 212, 2025), critical AI infrastructure risk management duty |
Through its governance duty. What it requires |
|
| AI Framework Act, Article 34 (business-operator duties for high-impact AI) |
Through its governance duty. What it requires |
|
| Law on Artificial Intelligence, risk classification and conformity assessment |
Through its governance duty. What it requires |
AI governance
11 laws, 8 placesShow the other 1 law
| Guidelines on Artificial Intelligence of Vatican City State (Decree No. DCCII) |
Through its content labelling, governance duties. What it requires |
AI sector rules
7 laws, 7 placesAI prohibited practices
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| Lov nr. 467 af 14. maj 2025, National Competent Authorities and Article 5 Enforcement |
Through its governance duty. What it requires |
AI training data
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| AI Act, Article 53 (obligations for providers of general-purpose AI models) |
Through its governance duty. What it requires |
Excerpts of the OWASP Top 10 for Agentic Applications, CC BY-SA 4.0. OWASP GenAI Security Project, Agentic Security Initiative, OWASP Top 10 for Agentic Applications 2026, https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/, licensed CC BY-SA 4.0 (https://creativecommons.org/licenses/by-sa/4.0/). Excerpted: only the first paragraph of each entry's Description is reproduced, verbatim. Every control of the framework.