AI Governance Library

AIUC-1: Crosswalks OWASP Top 10 For Agentic Applications

This crosswalk maps AIUC-1 requirements bidirectionally to the OWASP Top 10 for Agentic Applications. It classifies mappings as Primary or Secondary, assigns rationale codes, and identifies eight gaps in AIUC-1 coverage.
Cover of AIUC-1: Crosswalks OWASP Top 10 For Agentic Applications

⚡ Quick Summary

Published by OWASP GenAI Security Project, this guidance is a bidirectional crosswalk between AIUC-1 and the OWASP Top 10 for Agentic Applications (2026). It is intended to help practitioners using either framework understand the relationship between AIUC-1 requirements and ten agentic-security threats. AIUC-1 is presented as a security, safety and reliability standard structured around Data & Privacy, Security, Safety, Reliability, Accountability and Society; the OWASP Top 10 addresses risks facing autonomous and agentic systems.

The crosswalk provides two navigational views: from AIUC-1 requirements to relevant OWASP threats, and from each OWASP threat to relevant AIUC-1 requirements. It labels mappings Primary when they directly mitigate a threat's core risk and Secondary when they address a related consequence or supporting control. A controlled taxonomy assigns one of eight rationales: PREV, SCOPE, GATE, DETECT, VALID, GOVERN, ISOLATE and DISCLOSE. The document stresses that mappings indicate relevance rather than sufficient mitigation, and identifies eight areas where AIUC-1 may need new or expanded requirements for agentic threat modelling.

🧩 What’s Covered

The document progresses from the crosswalk's method and scope to two directional mapping views, gap analysis and reference material.

  • Purpose and structure: Introduces the relationship between AIUC-1 and the OWASP Top 10 for Agentic Applications, and explains the two mapping directions, the gap analysis, a master mapping table and related OWASP publications.
  • Mapping method: Defines Primary and Secondary relevance and the eight-function rationale taxonomy. It explains that relevance depends on threat context: for example, detection is Primary for persistent memory poisoning but Secondary where preventive controls are the frontline mitigation.
  • Scope of data and privacy controls: Extends the discussion beyond confidentiality to credential scoping, memory isolation, cross-context prevention, connector minimisation, telemetry and log-retention controls, and governance of embeddings, caches and retrieved context.
  • AIUC-1-to-OWASP mapping: Maps requirements across Data & Privacy, Security, Safety, Reliability, Accountability and Society to the ten threats. Examples include B006, preventing unauthorised AI agent actions, and D003, restricting unsafe tool calls, which each map broadly across the threat set.
  • OWASP-to-AIUC-1 mapping: Describes ASI01 through ASI10, including Agent Goal Hijack, Tool Misuse and Exploitation, Memory and Context Poisoning, Cascading Failures, Human-Agent Trust Exploitation and Rogue Agents. Each entry lists relevant AIUC-1 controls and their relevance level.
  • Gaps and proposed expansions: Sets out eight gaps covering inter-agent communication, identity attestation and containment, supply-chain attestation, cascading-failure containment, tool-use infrastructure, runtime monitoring, resource and cost abuse, and input/output schemas and determinism. It also records scope-expansion recommendations for C003/C004 guardrail placement and E011 data sovereignty.
  • Reference material: Appendix A supplies definitions and the master mapping table. Appendix B lists companion OWASP Agentic Security Initiative resources, followed by acknowledgements and project sponsor and supporter information.

💡 Why it matters?

Teams using AIUC-1 can use the crosswalk to locate the OWASP threat scenarios connected to their existing requirements; teams starting with the OWASP Top 10 can locate corresponding AIUC-1 controls. The Primary/Secondary distinction and rationale taxonomy help separate direct mitigation, scope restriction, human gates, detection, validation, governance, isolation and disclosure functions.

The document is also useful for identifying where control coverage should not be mistaken for completeness. It directs organisations to assess implementation depth, testing coverage and operational maturity against the prevention guidance for each specific threat.

❓ What’s Missing

The document explicitly says that it identifies relevance, not sufficiency, so it does not establish that mapped AIUC-1 requirements completely mitigate any threat. Its own gap analysis identifies missing or partial coverage for agent-to-agent authentication, per-agent identity attestation, kill switches, containment mechanisms, tool manifests, prompt version control, agent dependency bills of materials, runtime monitoring, entitlement protection and structured schemas at the agent-model boundary. It also notes that E015 logging does not explicitly extend to agent- or application-level tool activity. The crosswalk points readers to companion OWASP publications for deeper technical treatment rather than providing their implementation patterns in full.

👥 Best For

AI governance and security leads assessing AIUC-1 coverage of agentic threats; architects mapping controls for multi-agent systems, tools and deployment environments; and assurance teams planning adversarial, tool-call, harmful-output or hallucination testing. It is particularly suited to teams that need to compare governance requirements with concrete threat categories and control functions.

📄 Source Details

AIUC-1: Crosswalks OWASP Top 10 For Agentic Applications is a 55-page English-language document from the OWASP GenAI Security Project's Agentic Security Initiative. Version 1.0 is dated May 2026 and is licensed CC BY-SA 4.0. Co-authors are John Sotiropoulos and Kyriakos “Rock” Lambros. The printed project website is genai.owasp.org.

About the author
Jakub Szarmach

AI Governance Library

Curated Library of AI Governance Resources

AI Governance Library

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to AI Governance Library.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.