The AI Risk GapStanding
Thirty AI risks, and the one that maps to nothing
Updated 12 August 2026 · Timeframe: Current snapshot
OWASP names 30 AI security risks across its LLM, Agentic, and ML Top 10 lists. We mapped every one to the weakness catalog (CWE) and the attack catalog (ATLAS). Eighteen have no named weakness a scan could find. And one, ASI08 Cascading Agent Failures, maps to nothing at all — neither a weakness nor an attack technique. It sits, tellingly, in the newest list: agentic AI.
Why it matters
The vocabulary for what can go wrong with AI is running ahead of the vocabulary for defending it. If you deploy AI agents, a weakness scanner or control framework will not describe your real risk, because the standards barely define it yet.
What to do
- Security leaders. For AI agents, use the OWASP Agentic Top 10 as your risk list, but plan the defense as bespoke — six of ten have no weakness to scan for.
- Lean IT orgs. Ordinary vuln tools will not see agentic risk; read the OWASP Agentic Top 10 directly.
- MSPs. If clients run AI agents, agentic risk is outside the frameworks you report on today — flag it explicitly rather than assuming coverage.
Our take
Naming exactly where the AI defensive catalogs run out, from our own direct mappings, is the evidence-first AI framing the hype cycle skips.