Story perspectives
OWASP Updates AI Security Guidance, Identifies 21 Key Risks
4/6/2026
1 of 2
Story summary
- The Open Web Application Security Project (OWASP) updates AI security guidance, with guides for generative AI and agentic AI identifying 21 risks, including sensitive data leakage and unauthorized data flows.
- OWASP will switch to a six-month update cycle.
- Arkose Labs finds 97% of security leaders expect AI-driven incidents within a year, but only 6% of budgets address risk.
- Organizations must improve visibility and governance for AI agents to mitigate threats.
1 / 2
