Agent Risk Taxonomy

The first granular taxonomy that turns AI-risk standards into hands-on security controls.

AI Risk Taxonomy
7

Core Risk Domains

18

Risk Categories

6

Framework Mappings

100+

Specific Risk Scenarios

Built on Industry Standards

Mapped to the standards you already track.
Actionable Intelligence
Comprehensive Coverage
Engineering Ready
Actionable Intelligence
Comprehensive Coverage
Engineering Ready
Actionable Intelligence
Comprehensive Coverage
Engineering Ready

OWASP Top 10 for Agentic Applications (2026)

10/10 covered (ASI01–ASI10)

β€Ž

Mitre

MITRE ATLAS

Live tactics & techniques like AML.T0053 (Plugin Compromise)

Eu

EU AI Act

Direct references to Articles 9, 10, 14 + Annex III.

NIST

NIST AI RMF

Each risk slotted into Govern β†’ Map β†’ Measure β†’ Manage

ISO

ISO 42001 / 24028

Governance & trustworthiness clauses cross-linked.

AIUC-1

All six pillars mapped, A. Data & Privacy through F. Society.

Agent Risk Taxonomy

Privilege Escalation
ASI03
Privilege Escalation: Agents gain excessive permissions beyond their intended scope, potentially accessing or modifying resources they shouldn't. This often occurs through misconfigured access controls or exploiting system vulnerabilities.
Credential
Theft
ASI03
Credential Theft: Agent authentication credentials are compromised, allowing unauthorized access to systems and data. This includes stolen API keys, session tokens, or identity spoofing attacks.
Confused Deputy
ASI03
Confused Deputy: Agents are tricked into misusing their legitimate authority to perform unauthorized actions on behalf of attackers. This exploits the agent's trusted position while making malicious actions appear legitimate.
Goal Misalignment
ASI01, ASI10
Goal Misalignment: Agents pursue objectives that deviate from their intended purpose, often optimizing for metrics that don't align with actual business goals. This includes reward hacking where agents find unintended ways to maximize their success criteria.
Policy Drift
ASI01, ASI10
Policy Drift: The agent's behavior gradually changes over time, deviating from its original instructions and safety constraints. This can occur through cumulative exposure to biased inputs or subtle prompt modifications.
Hallucination
ASI08
Hallucination: Agents generate confident but factually incorrect information, often creating cascading errors when subsequent decisions are based on these false premises. This is particularly dangerous in high-stakes domains like finance or healthcare.
Bias & Toxicity
ASI09
Bias & Toxicity: Agents reflect harmful stereotypes or generate inappropriate content, leading to discriminatory outcomes or offensive responses. This includes demographic bias in recommendations and toxic language generation.
API Integration
ASI02
API Integration: Issues arise from changing API schemas, rate limits, or service unavailability that can break agent functionality. Agents may fail silently or make decisions based on stale or malformed data.
Supply Chain Vulnerabilities
ASI04
Supply-Chain Vulnerabilities: Compromised dependencies, libraries, or containers can introduce malicious behavior into agent systems. This includes backdoors in AI models or malicious code in third-party integrations.
Uncontrolled Resource Consumption
ASI02, ASI08
Uncontrolled Resource Consumption: Agents consume excessive computational resources through infinite loops, prompt storms, or recursive API calls. This can lead to denial-of-service conditions and unexpected infrastructure costs.
Sensitive Data Exposure
ASI06
Sensitive Data Exposure: Agents inadvertently reveal confidential information from training data, logs, or connected systems. This includes exposing personal identifiable information (PII) or proprietary business data.
Data Exfiltration Channel
ASI02, ASI06
Data Exfiltration Channels: Malicious actors use agents as conduits to steal data through covert channels or unauthorized transfers. This can involve encoding sensitive data in seemingly normal outputs or responses.
Unsafe Actuation
ASI02, ASI10
Unsafe Actuation: Agents perform destructive operations or are weaponized for malicious purposes, including unauthorized modifications to systems or data. This represents the most direct physical or digital harm potential.
Human Manipulation
ASI09
Human Manipulation: Agents mislead users, create over-reliance, or exploit psychological vulnerabilities to influence human behavior. This includes deceptive practices and undermining human decision-making autonomy.
Opaque Reasoning
Beyond the framework
Opaque Reasoning: Inability to trace or explain the agent's decision-making process, making it impossible to audit outcomes or debug failures. This creates compliance risks and hampers incident response efforts.
Data & Memory Poisoning
ASI06
Data & Memory Poisoning: Agents' knowledge bases or memory systems are corrupted with false information, leading to persistent misinformation. This includes attacks on retrieval-augmented generation (RAG) systems and vector databases.
Access Control & Permissions: Risks of agents obtaining or being granted unauthorized access to data and systems through privilege escalation, credential theft, confused deputy attacks, and forged or intercepted inter-agent messages. These bypass traditional security boundaries and create persistent access paths.
Tool Misuse: Risks arising from the failure, vulnerability, or improper use of external tools, APIs, and other dependencies. These include silent contract changes, supply chain compromises, uncontrolled resource consumption, and unsafe execution of agent-generated code that can lead to systemic failures when chained through agent workflows.
Governance: Risks related to agents deviating from their intended goals, rules, or instructions.
Agent Output Quality: Risks from agents generating false, biased, toxic, or otherwise harmful content.
Agent Behaviour: Risks of agents being manipulated or used to deceive users, perform harmful actions, or cause unintended consequences.
Privacy: Risks of agents inadvertently leaking, exposing, or exfiltrating sensitive data.
Reliability & Observability: Risks of performance degradation over time and an inability to understand or trace an agent's decision-making process.
Unsafe Code Execution
ASI05
Unsafe Code Execution: The agent treats code as just another output, emitting and executing it without the scrutiny applied to actions. It writes and runs scripts that reach beyond the task's data and network boundaries, accepts code fragments supplied in prompts or returned by tools and executes them as trusted, and composes shell or SQL strings from unvalidated input so that injected fragments run with the agent's privileges. Because the output looks like ordinary work product, these executions bypass the approval paths that equivalent tool calls would face.
Insecure Inter-Agent Communication
ASI07
Insecure Inter-Agent Communication: The agent extends to peer agents the trust it should reserve for authenticated principals. It accepts delegated tasks without verifying which agent issued them or on whose authority, treats instructions embedded in a peer's payload as commands rather than data, and relays requests onward while stripping the provenance a downstream agent would need to judge them. A single compromised or impersonated participant propagates injected instructions across the collaboration.
Access control
& Permission
Tool Misuse
Agent Behaviour
Governance
Privacy
Agent Output Quality
Reliability & observability
Agent Failure
Agent Misuse
Tool Failure
Agent Failure
Framework

close

ASI01 - ASI10

OWASP Top 10 for Agentic Applications (2026)
ASI01
Agent Goal Hijack
ASI02
Tool Misuse
ASI03
Identity & Privilege Abuse
ASI04
Agentic Supply Chain Vulnerabilities
ASI05
Unexpected Code Execution
ASI06
Memory & Context Poisoning
ASI07
Insecure Inter-Agent Communication
ASI08
Cascading Failures
ASI09
Human-Agent Trust Exploitation
ASI10
Rogue Agents
Agent Risk Taxonomy: 7 domains and 18 risks mapped to OWASP Top 10 for Agentic Applications (2026)

Mappings with existing frameworks

We mapped the agent risks with existing frameworks like OWASP, NIST, EU AI Act etc.

SEE
MORE
Risk Domain Category OWASP Top 10 for Agentic Applications (2026) MITRE ATLAS (ID + Name) NIST AI RMF ID(s) ISO AI Safety Standard(s) AIUC-1
Governance Goal Misalignment ASI01, ASI10 AML.T0053 – LLM Plugin Compromise GOVERN 1.2 TR 24028; 42001; 23894 E. Accountability
Governance Policy Drift ASI01, ASI10 AML.T0010 – AI Supply Chain Compromise GOVERN 1.5 TR 24028; 23894 E. Accountability
Agent Output Quality Hallucination ASI08 AML.T0062 - Discover LLM Hallucinations MEASURE 2.5 TR 24028; 24029-1 D. Reliability
Agent Output Quality Bias & Toxicity ASI09 AML.T0048 – External Harms MEASURE 2.11 TR 24028; 23894 F. Society
Tool Misuse API Integration ASI02 AML.T0053 - LLM Plugin Compromise MAP 2.2 TR 24028; 42001; 23894 D. Reliability
Tool Misuse Supply-Chain Vulnerabilities ASI04 AML.T0040 – AI Supply Chain Compromise MAP 4.1 TR 24028; 42001; 23894 B. Security
Tool Misuse Uncontrolled Resource Consumption ASI02, ASI08 AML.T0029 – Denial of ML Service MAP 3.2 TR 24028; 42001; 23894 D. Reliability
Tool Misuse Unsafe Code Execution ASI05 AML.T0053 – LLM Plugin Compromise MEASURE 2.7 TR 24028; 42001; 23894 B. Security
Privacy Sensitive Data Exposure ASI06 AML.T0057 - LLM Data Leakage MEASURE 2.10 TR 24028; 23894 A. Data & Privacy
Privacy Data Exfiltration Channels ASI02, ASI06 AML.T0024 - Exfiltration via AI Inference API MAP 4.2 TR 24028; 23894 A. Data & Privacy
Reliability & Observability Data & Memory Poisoning ASI06 AML.T0020 – Poison Training Data MEASURE 3.1 TR 24028; 24029-1; 23894 D. Reliability
Reliability & Observability Opaque Reasoning Beyond the framework: repudiation and untraceability AML.T0049 - Exploit Public-Facing Application MEASURE 2.9 TR 24028; 23894 E. Accountability
Agent Behaviour Human Manipulation ASI09 AML.T0054 - LLM Jailbreak MAP 5.1 TR 24028; 42001; 23894 C. Safety
Agent Behaviour Unsafe Actuation ASI02, ASI10 AML.T0048 – External Harms MEASURE 2.6; MANAGE 1.3 TR 24028; 24029-1; 23894 C. Safety
Access Control & Permissions Credential Theft ASI03 AML.T0012 – Valid Accounts MEASURE 2.7 TR 24028; 42001; 23894 B. Security
Access Control & Permissions Privilege Escalation ASI03 AML.T0055 – Unsecured Credentials GOVERN 6.1 TR 24028; 42001; 23894 B. Security
Access Control & Permissions Confused Deputy ASI03 AML.T0054 – LLM Jailbreak GOVERN 6.1 TR 24028; 42001; 23894 B. Security
Access Control & Permissions Insecure Inter-Agent Communication ASI07 AML.T0054 – LLM Jailbreak MEASURE 2.7 TR 24028; 42001; 23894 B. Security

Frequently Asked Questions

How is this different from general AI security?

We focus specifically on autonomous agents that use toolsβ€”not traditional ML models. The risks are fundamentally different.

Which agent types does this cover?

Any AI system that can invoke external APIs, make decisions autonomously, or interact with tools. Technology-agnostic.

How does this differ from traditional AI security frameworks?

Unlike traditional frameworks that focus on ML model security, our taxonomy specifically addresses the unique risks of agentic AI systems that can take autonomous actions and interact with external tools.

Is the framework applicable to all types of AI agents?

Yes, the taxonomy covers single-model agents, multi-agent systems, and any AI system that can invoke external tools or APIs autonomously. It's designed to be technology-agnostic.

Can my team contribute?

Yes! We welcome input from security practitioners. Contact us about our contributor program.

Get the complete Agent Risk Taxonomy & stay ahead of agent threats.