OWASP Releases: Securing Agentic Applications Guide v1.0 - Practical Security Guidance For Building Safer Agentic AI Systems
🚀 New Release: OWASP Securing Agentic Applications Guide v1.0, Practical Security Guidance for Building Safer Agentic AI Systems
As AI systems evolve toward more autonomous, tool-using, and multi-agent architectures, new security challenges emerge that traditional AppSec can’t handle alone. That’s why the Open Worldwide Application Security Project (OWASP) Gen AI Security Project has published the Securing Agentic Applications Guide v1.0, the most comprehensive and actionable open source security resource yet for Agentic AI developers and defenders.
What’s Inside:
✅ Secure design patterns for agentic workflows
✅ Threat mappings to the OWASP Top 10 for LLMs
✅ Hardening guidance for memory, tools, APIs, and orchestration
✅ Secure-by-design checklists across the entire SDLC
✅ Agent-specific threats like tool misuse, rogue agents, and goal hijacking
✅ Case studies on real-world multi-agent copilots and secure architecture patterns
Designed by developers and security practitioners for AI/ML engineers, software developers, AppSec pros, and anyone building or defending AI agents from single-agent applications to complex multi-agent architectures.
This guide aims to provide practical and actionable guidance for designing, developing, and deploying secure agentic applications powered by large language models (LLMs). It complements the OWASP Agentic AI Threats and Mitigations (ASI T&M) document by focusing on concrete technical recommendations that builders and defenders can apply directly.
Download the complete guide HERE
About Gen AI Security Project
Businesses, eager to harness the potential of LLMs and Generative AI are rapidly integrating them into their operations and client facing offerings. The OWASP Gen AI Security Project helps organizations and practitioners navigate the fast-changing generative AI landscape. With practical resources, risk strategies, and global collaboration, it enables confident innovation while reducing threats in LLMs, AI agents, and other generative AI technologies—fostering trust, compliance, and resilience.
Who is it for?
The OWASP Generative AI Security Project supports those shaping, building, and securing generative AI systems—including CISOs, IT leaders, security teams, engineers, developers, and policymakers. It offers practical guidance and open-source tools to manage the evolving security challenges of LLMs and generative AI.
Learn more about the OWASP Gen AI Security Project and become a contributor HERE
The countdown to Black Hat has begun, and XM Cyber is excited to showcase their latest innovations in Las Vegas.• Attendees are invited to visit booth 5439 for a demo of XM Cyber's Continuous Exposure Management solution and to receive a complimentary LEGO server and custom T-shirt.
🥂 XM Cyber & Google Cloud are bringing our partnership to life with EXPOSED – a private Happy Hour for cybersecurity leaders. Come hang out with us for great drinks and bar food. RSVP is required ->>> HERE 🍾🍹🍸🍻🍷🥳🎉
Explore the full agenda and activities taking place on August 6-7 by clicking below 👇🏻
Upskill your Team 🚀 Cyber Security Awareness
3wThis is a solid resource that we have been implementing internally
ICT security & governance adviser
3wA clear representation of the risks posed by the use of expert system-based tools.
A timely move in strengthening the foundations of AI deployment. As adoption grows, so does the need for robust security frameworks. Supporting teams through targeted #training and continuous #upskill can help build the capability needed to manage emerging risks. There’s also real value in exploring #techinnovation to develop smarter, more resilient systems.
GET SOCIAL, OR GET LOST! | Financial, FinTech, and Cybersecurity B2B Content Writer | FinTech and Wall Street Lead Generation
3wThis is a fantastic resource for navigating the complexities of agentic AI security. It’s inspiring to see OWASP providing such practical, actionable guidance that empowers developers to build with confidence. I particularly appreciate the focus on real-world application patterns, which makes the learning curve feel much more manageable. Looking forward to seeing how this advances AI safety across the board!
Cybersecurity Project Manager | Security Compliance Manager
3w🔐 The new OWASP Securing Agentic Applications Guide v1.0 is a major step forward—not just for developers, but also for vendor risk managers working with AI solutions. As AI vendors integrate tool-using, autonomous agents into their platforms, traditional third-party risk assessments aren't enough. This guide gives us a practical framework to ask smarter questions around LLM orchestration, memory handling, API exposure, and agent control boundaries. For anyone in vendor governance or security reviews, this is essential reading. It's time we start evaluating AI suppliers not just for compliance—but for how they secure their agentic behaviors.