The hardest AI security problems now live in what an agent is permitted to do
OWASP’s 2026 Top 10 for LLM applications moved excessive agency from sixth to third and dropped improper output handling from fifth to tenth, in the first edition weighted partly on incident data. Europe’s Cyber Resilience Act began requiring 24-hour vulnerability reports on 11 September, but it governs products rather than how an agent is deployed. […]
This story continues at The Next Web
Read more »