OWASP published their 2026 Top 10 for LLM Applications on September 1, and there's a number buried in it that should make every small org running AI tools stop and think.
Excessive Agency — the risk that your AI agent has too much power to act on its own — jumped from #6 to #3 on the list. It's the biggest positional shift in the 2026 edition. And this time, the ranking isn't based on expert vibes. It's based on 7,714 real AI security incidents that OWASP collected from practitioners across the community.
That's a lot of real organizations already getting burned by this. Most of them probably didn't see it coming.
What "Excessive Agency" Actually Means
The name sounds abstract. The reality is pretty concrete.
OWASP breaks it into three root causes:
Excessive functionality — Your AI agent can reach tools it doesn't need for the task. A document-summarization tool that also has access to your CRM. An email-drafting agent that's connected to your payment system. The tool scope is wider than the job.
Excessive permissions — Even the right tools have too much authority. A read-only feature authenticating with credentials that also hold UPDATE and DELETE rights. The agent can't see the boundary because you didn't build one.
Excessive autonomy — High-impact, irreversible actions are running without a human checkpoint. The agent deletes the record. The agent fires the email. The agent initiates the transfer. Nobody reviewed it first.
Three separate failure modes, but they share the same outcome: your AI does something you didn't want it to do, and by the time you find out, it already happened.
The previous OWASP list ranked this as a moderate risk. The 2026 update, weighted against actual incidents, says it's now your third-most-likely source of real damage. Behind only prompt injection and sensitive data disclosure.
Why Small Orgs Are Especially Exposed
If you're running a 10 to 50 person organization and you've started deploying AI agents — for customer responses, data processing, document workflows, scheduling — you probably built those tools fast. That's smart. Moving fast is why small orgs have an edge right now.
But fast-built tools tend to inherit full permissions from whoever set them up. If the person who built your AI email responder connected it to a Gmail account that also has access to your shared drive, your billing docs, and your HR folder, that's exactly the attack surface the 2026 OWASP list is describing.
And the issue isn't just external attackers. Prompt injection — still #1 on the list — means someone can feed your AI a malicious instruction through a document, an email, or a web page it's browsing. If that agent has excessive permissions when it's compromised, the blast radius grows to match.
One OWASP note that stuck with us: "A manipulated or unreliable model becomes significantly more dangerous when it can access sensitive or private information, update records, execute workflows, or trigger external systems without sufficient segmentation."
That's describing a lot of the agentic setups we see in the field. They work great — until one bad input hits them sideways.
The New Agent Control Standard
Alongside the updated Top 10, OWASP also released the Agent Control Standard v0.1 — a practical framework for organizations that want to govern their AI agents without building a 40-page policy document nobody reads.
Two pieces of the ACS matter for small orgs right now:
Agent Bill of Materials (ABoM) — A lightweight inventory of what your agent can access, what tools it's connected to, and what permissions it holds. Think of it as the manifest file for your AI setup. You probably don't have one. You should.
Runtime tracing via OpenTelemetry/OCSF — Structured logging for what your agent is actually doing in production. Not just whether it succeeded or failed — what it accessed, what it modified, what it tried to do. That's the difference between finding out something went wrong and knowing what went wrong.
None of this is rocket science. But it requires someone to sit down and actually build it. Most orgs skip this step because they're focused on getting the agent working.
Three Things to Do This Week
If you're running any agentic AI setup — a workflow automation, a customer-facing chatbot, a data processing agent — here's where to start:
1. Audit your agent's permissions. List every tool it's connected to and compare that list to what the task actually requires. Cut anything that isn't needed for the job. Use a dedicated service account or API key with the minimum scope, not your admin credentials.
2. Put human checkpoints on irreversible actions. Any action that writes to a database, sends an external communication, or initiates a financial transaction should have an approval step before it fires. Your agent can draft it. A human should confirm it.
3. Write down what your agent can access. Even a simple spreadsheet is a starting point for an ABoM. Tool name. What it connects to. What credentials it uses. What it can do. If you can't describe your agent's blast radius in plain language, you don't know it yet.
The 2026 OWASP list is useful because it reflects what's actually happening out there — not what security vendors are trying to sell you. Excessive Agency moving to #3 is a signal from 7,714 incidents worth of real organizations learning this lesson the hard way.
You don't need to wait for incident #7,715.
This is the kind of thing we walk through with teams in our AI readiness sprints — mapping what your agents can actually do, tightening the blast radius, and building the oversight layer so you stay in control when things go sideways. If you want a second set of eyes on your setup, get in touch.