Analysis · curated 30 Jul 2026
The OWASP Guide to AI Agent Security and Where Deception Fits
First reported acalvio.com
Coverage timeline
Single-source analysis — first reported, latest, and curated coincide.
Why it matters
OWASP's agentic AI guidance gives defenders a shared vocabulary for autonomous-agent risks like prompt injection and excessive agency, and the post highlights that preventive controls alone miss malicious intent that lives in an agent's sequence of otherwise-permitted actions.
Acalvio's post explains OWASP's agentic AI security guidance—the AI Agent Security Cheat Sheet, the Top 10 for LLM Applications, and the Top 10 for Agentic Applications (2026)—covering risks such as prompt injection (LLM01), excessive agency, and trust chain abuse, then argues that deception (decoy APIs, deceptive credentials, honeytokens) adds a runtime detection layer over existing SIEM/EDR/identity controls. The piece references the November 2025 GTG-1002 AI-orchestrated espionage campaign as motivation.