The 2026 OWASP Top 10 for LLM Applications, published August 4, reordered around agents: Excessive Agency climbed to third, Unbounded Consumption rose four places, and Improper Output Handling fell five. Behind the moves is a methodology change with an awkward result, since practitioners rank prompt injection first while the raw incident record drops it out of the top ten entirely. This guide walks all ten entries with the mechanism, a production failure, and the controls that hold, separating defenses that merely reduce attack success from the architectural bounds that survive an adaptive attacker.
Dario Amodei is right that capability-tiered testing isn't regulatory capture, it's a tax on being biggest. But investor David Sacks has a real counter: that same tax only holds if smaller labs actually clear the queue faster, and neither Amodei nor Gavin Baker is asking whether any lab can prove its safety claims at all.