{"id":15370,"date":"2026-09-17T18:00:29","date_gmt":"2026-09-17T12:30:29","guid":{"rendered":"https:\/\/threatcop.com\/blog\/?p=15370"},"modified":"2026-09-17T18:00:31","modified_gmt":"2026-09-17T12:30:31","slug":"attacks-against-ai-systems","status":"publish","type":"post","link":"https:\/\/threatcop.com\/blog\/attacks-against-ai-systems\/","title":{"rendered":"Attacks Against AI Systems: The Three Lists That Organise Them"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Attacks involving AI split into two categories: attacks carried out by AI, and attacks carried out against AI. The second is larger and less understood. Three OWASP lists now organise it, covering the model layer, the agent layer, and the tool-connection layer between them.<\/p><div id=\"ez-toc-container\" class=\"ez-toc-v2_0_87 ez-toc-wrap-center counter-hierarchy ez-toc-counter ez-toc-light-blue ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #414141;color:#414141\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #414141;color:#414141\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/threatcop.com\/blog\/attacks-against-ai-systems\/#Two_Categories_Not_One\" >Two Categories, Not One<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/threatcop.com\/blog\/attacks-against-ai-systems\/#The_Three_Lists_That_Organise_Attacks_Against_AI\" >The Three Lists That Organise Attacks Against AI<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/threatcop.com\/blog\/attacks-against-ai-systems\/#Book_a_Free_Demo_Call_with_Our_Expert\" >Book a Free Demo Call with Our Expert<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/threatcop.com\/blog\/attacks-against-ai-systems\/#The_Ten_Model-Layer_Risks\" >The Ten Model-Layer Risks<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/threatcop.com\/blog\/attacks-against-ai-systems\/#The_Agent-Layer_Risks_With_No_Model-Layer_Equivalent\" >The Agent-Layer Risks With No Model-Layer Equivalent<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/threatcop.com\/blog\/attacks-against-ai-systems\/#Read_the_List_as_Chains_Not_as_Ten_Items\" >Read the List as Chains, Not as Ten Items<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/threatcop.com\/blog\/attacks-against-ai-systems\/#What_Prompt_Injections_Ranking_Actually_Tells_You\" >What Prompt Injection&#8217;s Ranking Actually Tells You<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/threatcop.com\/blog\/attacks-against-ai-systems\/#Why_Your_Existing_AppSec_Tooling_Cannot_See_This\" >Why Your Existing AppSec Tooling Cannot See This<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/threatcop.com\/blog\/attacks-against-ai-systems\/#The_Incidents_Behind_the_List\" >The Incidents Behind the List<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/threatcop.com\/blog\/attacks-against-ai-systems\/#Two_Principles_That_Cover_Most_of_It\" >Two Principles That Cover Most of It<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/threatcop.com\/blog\/attacks-against-ai-systems\/#Where_the_Human_Layer_Sits_in_This\" >Where the Human Layer Sits in This<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-12\" href=\"https:\/\/threatcop.com\/blog\/attacks-against-ai-systems\/#Pick_One_Agent_and_Walk_the_Chain\" >Pick One Agent and Walk the Chain<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-13\" href=\"https:\/\/threatcop.com\/blog\/attacks-against-ai-systems\/#Frequently_Asked_Questions\" >Frequently Asked Questions<\/a><\/li><\/ul><\/nav><\/div>\n\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Two_Categories_Not_One\"><\/span>Two Categories, Not One<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Most coverage blurs them, and the blur produces budgets that cover neither properly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Attacks by AI are familiar attacks made faster and more convincing. Social engineering, vulnerability exploitation, and authentication attacks all get better when an attacker has generation and automation. The attack type does not change. Its yield does.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Attacks against AI are different in kind. Here the AI system is the target, and the techniques have no pre-AI equivalent. Poisoning a model&#8217;s memory is not a variant of anything defenders handled before 2023.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That distinction decides where money goes. Detecting AI-enhanced phishing does nothing to protect the agents in your own environment, and hardening those agents does nothing about AI-generated lures arriving in your inbox. Related ground appears in <a href=\"https:\/\/threatcop.com\/blog\/affects-of-ai-in-cybersecurity\/\">where AI is changing the threat picture<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"The_Three_Lists_That_Organise_Attacks_Against_AI\"><\/span>The Three Lists That Organise Attacks Against AI<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Long unstructured lists of AI attack names are common and hard to use. Three published taxonomies now do the organising, and each covers a distinct layer.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>List<\/strong><\/th><th><strong>Published<\/strong><\/th><th><strong>Layer it covers<\/strong><\/th><\/tr><\/thead><tbody><tr><td><a href=\"https:\/\/genai.owasp.org\/resource\/owasp-genai-llm-top-10-2026\/\" target=\"_blank\" rel=\"nofollow noopener\">OWASP Top 10 for LLM Applications 2026<\/a><\/td><td>3 August 2026<\/td><td>The model as a component inside an application<\/td><\/tr><tr><td><a href=\"https:\/\/genai.owasp.org\/resource\/owasp-top-10-for-agentic-applications-for-2026\/\" target=\"_blank\" rel=\"nofollow noopener\">OWASP Top 10 for Agentic Applications 2026<\/a><\/td><td>9 December 2025, updated to v2.01 on 1 June 2026<\/td><td>A system that plans, remembers, uses tools, and acts<\/td><\/tr><tr><td>OWASP MCP Top 10<\/td><td>Beta, entries MCP01:2025 to MCP10:2025<\/td><td>The tool-connection layer between an agent and external systems<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The division is clean. One list governs what a model says. Another governs what a system does. The third governs how it reaches the outside world.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">They stack rather than compete. The agentic list extends the LLM list rather than replacing it. Each agentic entry cross-references its model-layer counterparts, so an assessment runs top to bottom instead of choosing between frameworks.<\/p>\n\n\n\n<meta charset=\"UTF-8\">\n<meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n<title>Threatcop \u2013 Book a Free Demo<\/title>\n<link href=\"https:\/\/fonts.googleapis.com\/css2?family=Outfit:wght@300;400;500;600;700&#038;display=swap\" rel=\"stylesheet\">\n<style>\n  .tc-wrap , .tc-wrap ::before, .tc-wrap ::after { box-sizing: border-box; margin: 0; padding: 0; }\n  .tc-wrap { font-family: 'Outfit', sans-serif; width: 100%; display: flex; justify-content: center; padding: 20px 10px; }\n  .tc-card { width: 100%; max-width: 820px; background: #fff; border-radius: 20px; overflow: hidden; box-shadow: 0 20px 60px rgba(24,57,148,0.13), 0 4px 16px rgba(24,57,148,0.07); display: flex; flex-direction: row; }\n  .tc-left { background: linear-gradient(160deg, #1e44b0 0%, #183994 40%, #0e2570 100%); width: 320px; flex-shrink: 0; padding: 40px 32px; display: flex; flex-direction: column; justify-content: center; position: relative; overflow: hidden; }\n  .tc-left::before { content: ''; position: absolute; inset: 0; background-image: radial-gradient(rgba(255,255,255,0.08) 1.5px, transparent 1.5px); background-size: 22px 22px; }\n  .tc-left::after { content: ''; position: absolute; bottom: -60px; right: -60px; width: 220px; height: 220px; background: radial-gradient(circle, rgba(99,179,255,0.22) 0%, transparent 65%); border-radius: 50%; pointer-events: none; }\n  .tc-panel-inner { position: relative; z-index: 1; }\n  .tc-badge { display: inline-flex !important; align-items: center !important; gap: 6px; background: rgba(255,255,255,0.1) !important; border: 1px solid rgba(255,255,255,0.18) !important; border-radius: 20px !important; padding: 4px 14px 4px 10px !important; font-size: 12.5px !important; font-weight: 600 !important; letter-spacing: .09em !important; text-transform: uppercase !important; color: rgba(255,255,255,0.85) !important; margin-bottom: 18px !important; font-family: 'Outfit', sans-serif !important; line-height: 1.4 !important; }\n  .tc-badge-dot { width: 6px; height: 6px; background: #5cd9a0; border-radius: 50%; box-shadow: 0 0 6px #5cd9a0; flex-shrink: 0; display: inline-block; }\n  .tc-left h1, .tc-left h2, .tc-left h3, .tc-left h4, .tc-left h5, .tc-left h6 { color: #ffffff !important; font-family: 'Outfit', sans-serif !important; font-size: 28px !important; font-weight: 700 !important; line-height: 1.35 !important; letter-spacing: -0.3px !important; margin: 0 !important; padding: 0 !important; background: none !important; -webkit-text-fill-color: #ffffff !important; }\n  .tc-left h2 em { font-style: normal !important; color: #7ec8ff !important; -webkit-text-fill-color: #7ec8ff !important; }\n  .tc-left p, .tc-left .tc-sub { color: rgba(255,255,255,0.78) !important; -webkit-text-fill-color: rgba(255,255,255,0.78) !important; font-family: 'Outfit', sans-serif !important; font-size: 14px !important; font-weight: 300 !important; line-height: 1.65 !important; margin-top: 12px !important; background: none !important; }\n  .tc-right { flex: 1; padding: 32px 32px 28px; display: flex; flex-direction: column; justify-content: center; }\n  .tc-form-title { font-size: 13px !important; font-weight: 600 !important; letter-spacing: .12em; text-transform: uppercase; color: #8fa4cc !important; margin-bottom: 20px !important; display: flex !important; align-items: center !important; gap: 10px; font-family: 'Outfit', sans-serif !important; }\n  .tc-form-title::after { content: ''; flex: 1; height: 1px; background: #eef1fa; }\n  .tc-grid { display: grid; grid-template-columns: 1fr 1fr; gap: 14px; }\n  .tc-field { display: flex; flex-direction: column; gap: 5px; }\n  .tc-field.full { grid-column: 1 \/ -1; }\n  .tc-field label { font-size: 13px !important; font-weight: 600 !important; color: #3a4f7a !important; letter-spacing: .04em; text-transform: uppercase; font-family: 'Outfit', sans-serif !important; display: block !important; }\n  .tc-input-wrap { position: relative; display: flex; align-items: center; }\n  .tc-input-wrap .tc-fi { position: absolute; right: 12px; width: 15px; height: 15px; stroke: #c0ccdf; stroke-width: 1.8; pointer-events: none; fill: none; }\n  .tc-wrap input[type=\"text\"], .tc-wrap input[type=\"email\"], .tc-wrap input[type=\"number\"] { width: 100% !important; border: 1.5px solid #e2e9f7 !important; border-radius: 10px !important; padding: 9px 34px 9px 13px !important; font-family: 'Outfit', sans-serif !important; font-size: 15px !important; font-weight: 400 !important; color: #1e2d50 !important; background: #f8faff !important; outline: none !important; transition: border-color .2s, background .2s, box-shadow .2s; -moz-appearance: textfield; box-shadow: none !important; -webkit-text-fill-color: #1e2d50 !important; }\n  .tc-wrap input[type=\"number\"]::-webkit-inner-spin-button, .tc-wrap input[type=\"number\"]::-webkit-outer-spin-button { -webkit-appearance: none; }\n  .tc-wrap input::placeholder { color: #c0ccdf !important; -webkit-text-fill-color: #c0ccdf !important; opacity: 1; }\n  .tc-wrap input:focus { border-color: #183994 !important; background: #fff !important; box-shadow: 0 0 0 3.5px rgba(24,57,148,0.1) !important; }\n  .tc-phone-row { display: flex; gap: 8px; }\n  .tc-flag-select { position: relative; flex-shrink: 0; }\n  .tc-flag-select select { appearance: none !important; -webkit-appearance: none !important; border: 1.5px solid #e2e9f7 !important; border-radius: 10px !important; padding: 9px 26px 9px 12px !important; font-family: 'Outfit', sans-serif !important; font-size: 14px !important; font-weight: 500 !important; color: #1e2d50 !important; background: #f8faff !important; outline: none !important; cursor: pointer; width: 100px !important; transition: border-color .2s, box-shadow .2s; }\n  .tc-flag-select select:focus { border-color: #183994 !important; box-shadow: 0 0 0 3.5px rgba(24,57,148,0.1) !important; }\n  .tc-flag-select::after { content: ''; position: absolute; right: 10px; top: 50%; transform: translateY(-50%); width: 0; height: 0; border-left: 4px solid transparent; border-right: 4px solid transparent; border-top: 5px solid #a0b0cc; pointer-events: none; }\n  .tc-phone-row .tc-input-wrap { flex: 1; }\n  .tc-btn-submit { width: 100% !important; margin-top: 18px !important; padding: 11px !important; background: #183994 !important; border: none !important; border-radius: 10px !important; color: #fff !important; -webkit-text-fill-color: #fff !important; font-family: 'Outfit', sans-serif !important; font-size: 15px !important; font-weight: 600 !important; letter-spacing: .05em; cursor: pointer; display: flex !important; align-items: center !important; justify-content: center !important; gap: 9px; transition: background .2s, transform .15s, box-shadow .2s; box-shadow: 0 6px 24px rgba(24,57,148,0.28) !important; text-decoration: none !important; }\n  .tc-btn-submit:hover { background: #1d46b5 !important; transform: translateY(-1px); box-shadow: 0 10px 32px rgba(24,57,148,0.35) !important; color: #fff !important; }\n  .tc-btn-submit:active { transform: translateY(0); }\n  .tc-btn-submit svg { width: 16px; height: 16px; stroke: #fff; stroke-width: 2.2; fill: none; flex-shrink: 0; }\n  .tc-trust { margin-top: 10px !important; display: flex !important; align-items: center !important; justify-content: center !important; gap: 5px; font-size: 13px !important; color: #a0b0cc !important; font-family: 'Outfit', sans-serif !important; }\n  .tc-trust svg { width: 12px; height: 12px; stroke: #a0b0cc; stroke-width: 2; fill: none; flex-shrink: 0; }\n  @media (max-width: 680px) {\n    .tc-card { flex-direction: column !important; }\n    .tc-left { width: 100% !important; padding: 28px 24px 24px !important; }\n    .tc-right { padding: 24px 20px !important; }\n    .tc-grid { grid-template-columns: 1fr !important; }\n    .tc-field.full { grid-column: 1 !important; }\n  }\n<\/style>\n\n<div class=\"tc-wrap\">\n  <div class=\"tc-card\">\n    <div class=\"tc-left\">\n      <div class=\"tc-panel-inner\">\n        <div class=\"tc-badge\">\n          <span class=\"tc-badge-dot\"><\/span>\n          People Security Management\n        <\/div>\n        <h2><span class=\"ez-toc-section\" id=\"Book_a_Free_Demo_Call_with_Our_Expert\"><\/span>Book a Free<br><em>Demo Call<\/em><br>with Our Expert<span class=\"ez-toc-section-end\"><\/span><\/h2>\n        <p class=\"tc-sub\">Discover how Threatcop protects your workforce from modern cyber threats.<\/p>\n      <\/div>\n    <\/div>\n    <div class=\"tc-right\">\n      <div class=\"tc-form-title\">Your Details<\/div>\n      <form action=\"https:\/\/threatcop.com\/thankyou-blog\" method=\"get\" target=\"_blank\">\n        <input type=\"hidden\" name=\"BlogForm\" value=\"BlogForm\">\n        <input type=\"hidden\" name=\"PageSource\" id=\"tc-page-source\" value=\"\">\n        <div class=\"tc-grid\">\n          <div class=\"tc-field\">\n            <label>Full Name<\/label>\n            <div class=\"tc-input-wrap\">\n              <input type=\"text\" name=\"FullName\" placeholder=\"Jane Smith\" required=\"\">\n              <svg class=\"tc-fi\" viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><circle cx=\"12\" cy=\"8\" r=\"4\"><\/circle><path d=\"M4 20c0-4 3.58-7 8-7s8 3 8 7\"><\/path><\/svg>\n            <\/div>\n          <\/div>\n          <div class=\"tc-field\">\n            <label>Company Name<\/label>\n            <div class=\"tc-input-wrap\">\n              <input type=\"text\" name=\"CompanyName\" placeholder=\"Acme Corp\" required=\"\">\n              <svg class=\"tc-fi\" viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><rect x=\"3\" y=\"3\" width=\"18\" height=\"18\" rx=\"2\"><\/rect><path d=\"M9 3v18M3 9h6M3 15h6\"><\/path><\/svg>\n            <\/div>\n          <\/div>\n          <div class=\"tc-field full\">\n            <label>Corporate Email<\/label>\n            <div class=\"tc-input-wrap\">\n              <input type=\"email\" name=\"email\" placeholder=\"jane@yourcompany.com\" required=\"\">\n              <svg class=\"tc-fi\" viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><rect x=\"2\" y=\"4\" width=\"20\" height=\"16\" rx=\"2\"><\/rect><polyline points=\"2,4 12,13 22,4\"><\/polyline><\/svg>\n            <\/div>\n          <\/div>\n          <div class=\"tc-field full\">\n            <label>Phone Number<\/label>\n            <div class=\"tc-input-wrap\">\n              <input type=\"number\" name=\"Phone\" placeholder=\"98765 43210\" required=\"\">\n              <svg class=\"tc-fi\" viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><path d=\"M22 16.92v3a2 2 0 01-2.18 2A19.79 19.79 0 013.09 4.18 2 2 0 015.07 2h3a2 2 0 012 1.72c.13.96.36 1.9.71 2.81a2 2 0 01-.45 2.11L9.09 9.91a16 16 0 006 6l1.27-1.27a2 2 0 012.11-.45c.91.35 1.85.58 2.81.71A2 2 0 0122 16.92z\"><\/path><\/svg>\n            <\/div>\n          <\/div>\n        <\/div>\n        <button type=\"submit\" class=\"tc-btn-submit\">\n          <svg viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><path d=\"M22 2L11 13M22 2L15 22l-4-9-9-4 20-7z\"><\/path><\/svg>\n          Book My Free Demo\n        <\/button>\n        <div class=\"tc-trust\">\n          <svg viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><rect x=\"3\" y=\"11\" width=\"18\" height=\"11\" rx=\"2\"><\/rect><path d=\"M7 11V7a5 5 0 0110 0v4\"><\/path><\/svg>\n          Your data is safe &amp; never shared with third parties\n        <\/div>\n      <\/form>\n    <\/div>\n  <\/div>\n<\/div>\n<script>document.getElementById('tc-page-source').value = window.location.href;<\/script>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"The_Ten_Model-Layer_Risks\"><\/span>The Ten Model-Layer Risks<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The 2026 LLM list runs in this order, and the order reflects both practitioner voting and incident data.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>ID<\/strong><\/th><th><strong>Risk<\/strong><\/th><th><strong>What it means in plain terms<\/strong><\/th><\/tr><\/thead><tbody><tr><td>LLM01<\/td><td>Prompt Injection<\/td><td>Untrusted text is read as instruction because data and commands share one context window<\/td><\/tr><tr><td>LLM02<\/td><td>Sensitive Information Disclosure<\/td><td>The model reveals data it held, was trained on, or was given<\/td><\/tr><tr><td>LLM03<\/td><td>Excessive Agency<\/td><td>The system can do more than its task requires, so a manipulation becomes an action<\/td><\/tr><tr><td>LLM04<\/td><td>Supply Chain<\/td><td>Compromised models, packages, datasets, or plugins enter before deployment<\/td><\/tr><tr><td>LLM05<\/td><td>Data and Model Poisoning<\/td><td>Training or fine-tuning data is corrupted to shape later behaviour<\/td><\/tr><tr><td>LLM06<\/td><td>Unbounded Consumption<\/td><td>Resource exhaustion and runaway cost, the AI-era denial of service<\/td><\/tr><tr><td>LLM07<\/td><td>Misinformation<\/td><td>Confident wrong output that downstream systems or people act on<\/td><\/tr><tr><td>LLM08<\/td><td>Hidden Context Exposure<\/td><td>Context the user cannot see leaks or influences results<\/td><\/tr><tr><td>LLM09<\/td><td>Vector and Embedding Weaknesses<\/td><td>Retrieval stores are manipulated, so the model retrieves attacker content<\/td><\/tr><tr><td>LLM10<\/td><td>Improper Output Handling<\/td><td>Model output reaches a shell, database, or browser without validation<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Two entries reward a second look. LLM03 rose from sixth place in the 2025 edition, which tracks how much real authority AI systems gained in a year. And LLM10 is the oldest idea on the list wearing new clothes. Passing unvalidated output into an interpreter is an injection flaw defenders have handled for decades.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"The_Agent-Layer_Risks_With_No_Model-Layer_Equivalent\"><\/span>The Agent-Layer Risks With No Model-Layer Equivalent<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Once a model stops generating text and starts acting, new categories appear. The agentic list numbers its entries ASI01 to ASI10, and the following are the ones documented in published coverage.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>ASI01 Agent Goal Hijack.<\/strong> An attacker redirects the agent&#8217;s objective through content it reads, so it pursues their goal while appearing to work normally<\/li>\n\n\n\n<li><strong>ASI02 Tool Misuse and Exploitation.<\/strong> The agent&#8217;s legitimate tools are turned against the systems they reach<\/li>\n\n\n\n<li><strong>ASI03 Identity and Privilege Abuse.<\/strong> The agent&#8217;s identity and standing permissions are used beyond their intent<\/li>\n\n\n\n<li><strong>ASI04 Supply Chain.<\/strong> Components discovered and integrated at runtime, rather than at build time<\/li>\n\n\n\n<li><strong>ASI06 Memory and Context Poisoning.<\/strong> Persistent memory is corrupted, so bad instructions survive across sessions<\/li>\n\n\n\n<li><strong>ASI07 Insecure Inter-Agent Communication.<\/strong> Traffic between agents is intercepted, impersonated, or manipulated<\/li>\n\n\n\n<li><strong>ASI10 Rogue Agents.<\/strong> An agent operating outside its intended purpose, whether hijacked or simply drifting<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Notably, ASI06 is the one that surprises people. A poisoned memory is not a single bad response. It is a bad instruction that persists, which makes it closer to a backdoor than to a prompt.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Read_the_List_as_Chains_Not_as_Ten_Items\"><\/span>Read the List as Chains, Not as Ten Items<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Treating a top ten as ten separate problems produces a plan that fails in the middle. Real incidents combine entries.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In practice the pattern is consistent. ASI01 and ASI06 are entry points, where an attacker gets their instruction into the system. ASI02 and ASI05 are where the attack cashes out, converting that instruction into an action with consequences.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Most real incidents pair one of each. Therefore, closing only the entry point, or only the impact, leaves the chain alive.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That has a practical implication for prioritisation. A team that spends everything on prompt injection filtering and nothing on tool scoping has hardened one end of a two-ended problem. Permission scoping details sit in <a href=\"https:\/\/threatcop.com\/blog\/anand-thangaraju-on-ai-automation-and-the-governance-layer\/\">governing what automation is allowed to do<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_Prompt_Injections_Ranking_Actually_Tells_You\"><\/span>What Prompt Injection&#8217;s Ranking Actually Tells You<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Prompt injection held the top LLM position again in 2026. The way it got there is more interesting than the result.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The two inputs to the ranking disagreed sharply. Practitioners voted it first. Incident data alone would have dropped it out of the top ten entirely.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">OWASP attributes that low incident count to years of defensive investment rather than to a shrinking attack surface. The surface still sits everywhere a model reads untrusted input, which is everywhere.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So the ranking is a statement about attention rather than frequency. Read it as a warning that the defences suppressing those incident numbers are load-bearing, and that removing them returns the problem immediately.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Why_Your_Existing_AppSec_Tooling_Cannot_See_This\"><\/span>Why Your Existing AppSec Tooling Cannot See This<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Security teams often assume their application security stack extends to AI features. Largely, it does not.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Traditional static analysis and software composition analysis inspect code and dependencies. They cannot see an agent&#8217;s prompts, its tools, its memory, or the traffic between agents. Those live in a layer the tooling was never built to examine.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The consequence is a visibility gap that looks like coverage. A clean SAST report on a repository says nothing about whether the agent that repository deploys holds a standing credential to a production database.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Closing it needs runtime observability rather than more scanning: what the agent did, why it did it, and under whose identity. Visibility problems of this shape appear in <a href=\"https:\/\/threatcop.com\/blog\/enterprise-security-platforms-for-ciso-visibility\/\">why security tooling misses the agent layer<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"The_Incidents_Behind_the_List\"><\/span>The Incidents Behind the List<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The agentic list is deliberately incident-driven, with nearly every entry anchored to a public 2025 or 2026 event. Three make the categories concrete.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">EchoLeak, tracked as CVE-2025-32711, demonstrated zero-click data exfiltration, meaning the victim did not have to interact for data to leave.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Amazon Q compromise weaponised a coding assistant with more than 950,000 installs, turning a trusted developer tool into a distribution channel.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And Replit&#8217;s agent deleted a production database during a code freeze, which is the clearest illustration available that agent risk is about authority rather than intelligence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That grounding is what makes the list usable as an audit checklist rather than an awareness poster.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Two_Principles_That_Cover_Most_of_It\"><\/span>Two Principles That Cover Most of It<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Underneath the taxonomy sit two ideas, and holding them is more useful than memorising twenty identifiers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Least agency is the first. It limits not only what an agent can access, but how much it can do without checking back with a human. Access scoping alone is insufficient once a system can chain many steps together.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Strong observability is the second. Seeing what an agent did, why, and under whose identity is what turns an incident into something investigable.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Importantly, neither requires a product. Both require decisions about authority and logging that most teams have not yet made, which is why the gap persists even in organisations with mature application security.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Where_the_Human_Layer_Sits_in_This\"><\/span>Where the Human Layer Sits in This<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Nothing in the taxonomy is purely technical, because somebody grants each permission the attacks exploit.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An employee approves an OAuth scope during setup. A developer connects an agent to a database because the task needed it that afternoon. Someone installs a marketplace component without reading what it does. Each is a security decision made by a person who may not know they made one.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Threatcop&#8217;s TLMS delivers role-specific content for exactly those moments, so developers wiring agents and staff approving connections get different scenarios rather than a shared AI module. Programme design for that sits in <a href=\"https:\/\/threatcop.com\/blog\/role-based-security-awareness-training\/\">training built around what each team does<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Pick_One_Agent_and_Walk_the_Chain\"><\/span>Pick One Agent and Walk the Chain<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Take a single AI system running in your environment. Identify its entry points, meaning everywhere it reads content somebody else controls. Then identify its cash-out points, meaning every tool it can call and every credential it holds.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Most teams find the two lists are maintained by different people who have never compared them. That gap is the chain the taxonomy describes, and closing it does not need a new product.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Then look at who granted the permissions on the second list, and <a href=\"https:\/\/threatcop.com\/people-security-management\">make sure those people understand what they approved<\/a> before the next integration ships.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Frequently_Asked_Questions\"><\/span>Frequently Asked Questions<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\t\t<div class=\"sp-easy-accordion-block sp-eab-regular-accordion alignwide\"\n\t\t\t\t>\n\t\t\t<div class=\"sp-eab-wrapper sp-eab-vertical-accordion sp-eab-c7c5c6ddf81b\">\n\t\t\t\t\t\t\t\t<div class='sp-eab-accordion sp-eab-mode-vertical sp-eab-vertical-one sp-d-flex' data-accordion-settings=\"{&quot;mode&quot;:&quot;vertical&quot;,&quot;activeEvent&quot;:&quot;click&quot;,&quot;defaultAccordionOpen&quot;:&quot;first-item&quot;,&quot;selectedItemOpen&quot;:0,&quot;openMultiItemAtaTime&quot;:false,&quot;scrollToTopOnLoad&quot;:false,&quot;scrollToTopOnClick&quot;:false,&quot;accordionItemToUrl&quot;:false,&quot;animationEffect&quot;:false,&quot;applyAccessibility&quot;:true}\">\n        \t    \t\n\t\t\t<div\n\t\t\t\tid =\"sp-eab-item-fbc4a0a928e8\"\n\t\t\t\tclass=\"sp-eab-accordion-item eab-item-ddf81b\"\n\t\t\t\t\t\t\t>\n\t\t\t\t<div class=\"sp-eab-accordion-item-wrapper\">\n\t\t\t\t\t\t\t\t<h3 class='sp-eab-accordion-heading sp-d-flex sp-align-center eab-heading-ddf81b'\n\t\t\t\t\t\t>\n\t\t\t\t<span class='sp-eab-accordion-header-wrapper sp-d-flex sp-align-center eab-icon-position-end'>\n\t\t\t\t\t<span class='sp-eab-accordion-header-start sp-d-flex sp-justify-left sp-align-center'>\n\t\t\t\t\t\t<span class='sp-eab-title-subtitle-wrapper sp-d-flex'>\n\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-wrapper sp-d-flex sp-align-center'>\n\t\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-text'>\n\t\t\t\t\t\t\t\t\tWhat are the main types of attacks against AI systems?\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<span class='sp-eab-accordion-header-end eab-icon-animated'>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class='sp-eab-expand-collapse-icon sp-d-block'>\n\t\t\t\t\t\t\t<i class='sp-eab-expand-icon eab-icon-angle-down-solid'><\/i>\n\t\t\t\t\t\t\t<i class='sp-eab-collapse-icon eab-icon-angle-up-solid'><\/i>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span>\n\t\t\t<\/h3>\n\t\t\t\t\t\t\t<!-- accordion body -->\n\t\t\t\t\t<div class='sp-eab-accordion-content eab-content-ddf81b'>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class='sp-eab-accordion-content-wrapper'>\n\t\t\t\t\t\t\t<div class='sp-eab-accordion-body'>\n\t\t\t    \t\t\t\t\n\n<p class=\"wp-block-paragraph\">Three OWASP taxonomies organise them. The Top 10 for LLM Applications 2026 covers the model layer. Its entries are prompt injection, sensitive information disclosure, excessive agency, supply chain, data and model poisoning, unbounded consumption, misinformation, hidden context exposure, vector and embedding weaknesses, and improper output handling. The Agentic Top 10 covers risks appearing once a system acts. The MCP Top 10 covers the tool-connection layer.<\/p>\n\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\n\n\t\t\t<div\n\t\t\t\tid =\"sp-eab-item-402870472965\"\n\t\t\t\tclass=\"sp-eab-accordion-item eab-item-ddf81b\"\n\t\t\t\t\t\t\t>\n\t\t\t\t<div class=\"sp-eab-accordion-item-wrapper\">\n\t\t\t\t\t\t\t\t<h3 class='sp-eab-accordion-heading sp-d-flex sp-align-center eab-heading-ddf81b'\n\t\t\t\t\t\t>\n\t\t\t\t<span class='sp-eab-accordion-header-wrapper sp-d-flex sp-align-center eab-icon-position-end'>\n\t\t\t\t\t<span class='sp-eab-accordion-header-start sp-d-flex sp-justify-left sp-align-center'>\n\t\t\t\t\t\t<span class='sp-eab-title-subtitle-wrapper sp-d-flex'>\n\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-wrapper sp-d-flex sp-align-center'>\n\t\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-text'>\n\t\t\t\t\t\t\t\t\tWhat is the difference between attacks by AI and attacks against AI?\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<span class='sp-eab-accordion-header-end eab-icon-animated'>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class='sp-eab-expand-collapse-icon sp-d-block'>\n\t\t\t\t\t\t\t<i class='sp-eab-expand-icon eab-icon-angle-down-solid'><\/i>\n\t\t\t\t\t\t\t<i class='sp-eab-collapse-icon eab-icon-angle-up-solid'><\/i>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span>\n\t\t\t<\/h3>\n\t\t\t\t\t\t\t<!-- accordion body -->\n\t\t\t\t\t<div class='sp-eab-accordion-content eab-content-ddf81b'>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class='sp-eab-accordion-content-wrapper'>\n\t\t\t\t\t\t\t<div class='sp-eab-accordion-body'>\n\t\t\t    \t\t\t\t\n\n<p class=\"wp-block-paragraph\">Attacks by AI are conventional techniques made faster and more convincing through generation and automation, such as AI-written phishing or automated vulnerability discovery. Attacks against AI target the AI system itself through techniques with no pre-AI equivalent, including prompt injection, memory poisoning, and agent goal hijacking. They need separate controls and separate budgets.<\/p>\n\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\n\n\t\t\t<div\n\t\t\t\tid =\"sp-eab-item-76a91192f7a7\"\n\t\t\t\tclass=\"sp-eab-accordion-item eab-item-ddf81b\"\n\t\t\t\t\t\t\t>\n\t\t\t\t<div class=\"sp-eab-accordion-item-wrapper\">\n\t\t\t\t\t\t\t\t<h3 class='sp-eab-accordion-heading sp-d-flex sp-align-center eab-heading-ddf81b'\n\t\t\t\t\t\t>\n\t\t\t\t<span class='sp-eab-accordion-header-wrapper sp-d-flex sp-align-center eab-icon-position-end'>\n\t\t\t\t\t<span class='sp-eab-accordion-header-start sp-d-flex sp-justify-left sp-align-center'>\n\t\t\t\t\t\t<span class='sp-eab-title-subtitle-wrapper sp-d-flex'>\n\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-wrapper sp-d-flex sp-align-center'>\n\t\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-text'>\n\t\t\t\t\t\t\t\t\tWhat is agent goal hijacking?\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<span class='sp-eab-accordion-header-end eab-icon-animated'>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class='sp-eab-expand-collapse-icon sp-d-block'>\n\t\t\t\t\t\t\t<i class='sp-eab-expand-icon eab-icon-angle-down-solid'><\/i>\n\t\t\t\t\t\t\t<i class='sp-eab-collapse-icon eab-icon-angle-up-solid'><\/i>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span>\n\t\t\t<\/h3>\n\t\t\t\t\t\t\t<!-- accordion body -->\n\t\t\t\t\t<div class='sp-eab-accordion-content eab-content-ddf81b'>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class='sp-eab-accordion-content-wrapper'>\n\t\t\t\t\t\t\t<div class='sp-eab-accordion-body'>\n\t\t\t    \t\t\t\t\n\n<p class=\"wp-block-paragraph\">Agent goal hijacking is ASI01 in the OWASP Top 10 for Agentic Applications. An adversary redirects the agent&#8217;s objective or decision path using content the agent reads. The agent then pursues the attacker&#8217;s goal while appearing to operate normally, which is harder to spot than an obvious malfunction.<\/p>\n\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\n\n\t\t\t<div\n\t\t\t\tid =\"sp-eab-item-9e9771cec73f\"\n\t\t\t\tclass=\"sp-eab-accordion-item eab-item-ddf81b\"\n\t\t\t\t\t\t\t>\n\t\t\t\t<div class=\"sp-eab-accordion-item-wrapper\">\n\t\t\t\t\t\t\t\t<h3 class='sp-eab-accordion-heading sp-d-flex sp-align-center eab-heading-ddf81b'\n\t\t\t\t\t\t>\n\t\t\t\t<span class='sp-eab-accordion-header-wrapper sp-d-flex sp-align-center eab-icon-position-end'>\n\t\t\t\t\t<span class='sp-eab-accordion-header-start sp-d-flex sp-justify-left sp-align-center'>\n\t\t\t\t\t\t<span class='sp-eab-title-subtitle-wrapper sp-d-flex'>\n\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-wrapper sp-d-flex sp-align-center'>\n\t\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-text'>\n\t\t\t\t\t\t\t\t\tDoes traditional application security tooling cover AI risks?\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<span class='sp-eab-accordion-header-end eab-icon-animated'>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class='sp-eab-expand-collapse-icon sp-d-block'>\n\t\t\t\t\t\t\t<i class='sp-eab-expand-icon eab-icon-angle-down-solid'><\/i>\n\t\t\t\t\t\t\t<i class='sp-eab-collapse-icon eab-icon-angle-up-solid'><\/i>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span>\n\t\t\t<\/h3>\n\t\t\t\t\t\t\t<!-- accordion body -->\n\t\t\t\t\t<div class='sp-eab-accordion-content eab-content-ddf81b'>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class='sp-eab-accordion-content-wrapper'>\n\t\t\t\t\t\t\t<div class='sp-eab-accordion-body'>\n\t\t\t    \t\t\t\t\n\n<p class=\"wp-block-paragraph\">Not adequately. Static analysis and software composition analysis inspect code and dependencies, but cannot see an agent&#8217;s prompts, tools, memory, or inter-agent traffic. Agentic attacks occur in a layer most application security tooling never inspects. A clean scan report can therefore coexist with an agent holding standing credentials to production.<\/p>\n\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\n\n\t\t\t<div\n\t\t\t\tid =\"sp-eab-item-b42ffff9e436\"\n\t\t\t\tclass=\"sp-eab-accordion-item eab-item-ddf81b\"\n\t\t\t\t\t\t\t>\n\t\t\t\t<div class=\"sp-eab-accordion-item-wrapper\">\n\t\t\t\t\t\t\t\t<h3 class='sp-eab-accordion-heading sp-d-flex sp-align-center eab-heading-ddf81b'\n\t\t\t\t\t\t>\n\t\t\t\t<span class='sp-eab-accordion-header-wrapper sp-d-flex sp-align-center eab-icon-position-end'>\n\t\t\t\t\t<span class='sp-eab-accordion-header-start sp-d-flex sp-justify-left sp-align-center'>\n\t\t\t\t\t\t<span class='sp-eab-title-subtitle-wrapper sp-d-flex'>\n\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-wrapper sp-d-flex sp-align-center'>\n\t\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-text'>\n\t\t\t\t\t\t\t\t\tIs prompt injection still the top AI security risk?\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<span class='sp-eab-accordion-header-end eab-icon-animated'>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class='sp-eab-expand-collapse-icon sp-d-block'>\n\t\t\t\t\t\t\t<i class='sp-eab-expand-icon eab-icon-angle-down-solid'><\/i>\n\t\t\t\t\t\t\t<i class='sp-eab-collapse-icon eab-icon-angle-up-solid'><\/i>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span>\n\t\t\t<\/h3>\n\t\t\t\t\t\t\t<!-- accordion body -->\n\t\t\t\t\t<div class='sp-eab-accordion-content eab-content-ddf81b'>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class='sp-eab-accordion-content-wrapper'>\n\t\t\t\t\t\t\t<div class='sp-eab-accordion-body'>\n\t\t\t    \t\t\t\t\n\n<p class=\"wp-block-paragraph\">Prompt injection remains LLM01 in the 2026 edition, though the ranking inputs disagreed. Practitioners voted it first, while incident data alone would have placed it outside the top ten. OWASP attributes the low incident count to sustained defensive investment rather than a shrinking attack surface, which still exists wherever a model reads untrusted input.<\/p>\n\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Attacks against AI target the system itself, not your inbox. See the three OWASP lists covering the model, agent, and tool layers, and how they chain.<\/p>\n","protected":false},"author":28,"featured_media":15385,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[424],"tags":[],"class_list":["post-15370","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Attacks Against AI Systems: The Taxonomy, Organised<\/title>\n<meta name=\"description\" content=\"Attacks against AI now have three OWASP taxonomies. See the model, agent, and tool layers explained, the incidents behind them, and how the chains connect.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/threatcop.com\/blog\/attacks-against-ai-systems\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Attacks Against AI Systems: The Taxonomy, Organised\" \/>\n<meta property=\"og:description\" content=\"Attacks against AI now have three OWASP taxonomies. See the model, agent, and tool layers explained, the incidents behind them, and how the chains connect.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/threatcop.com\/blog\/attacks-against-ai-systems\/\" \/>\n<meta property=\"og:site_name\" content=\"Threatcop\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/people\/Threatcop\/100083109892339\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-17T12:30:29+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-17T12:30:31+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Attacks-Against-AI-Systems-blog-banner.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"720\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Sushant Sharma\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatcop\" \/>\n<meta name=\"twitter:site\" content=\"@threatcop\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sushant Sharma\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/attacks-against-ai-systems\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/attacks-against-ai-systems\\\/\"},\"author\":{\"name\":\"Sushant Sharma\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#\\\/schema\\\/person\\\/1dcc018f2b81f296caf1a9e6cdd7c355\"},\"headline\":\"Attacks Against AI Systems: The Three Lists That Organise Them\",\"datePublished\":\"2026-09-17T12:30:29+00:00\",\"dateModified\":\"2026-09-17T12:30:31+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/attacks-against-ai-systems\\\/\"},\"wordCount\":1842,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/attacks-against-ai-systems\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Attacks-Against-AI-Systems-blog-banner.png\",\"articleSection\":[\"AI &amp; Cybersecurity\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/threatcop.com\\\/blog\\\/attacks-against-ai-systems\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/attacks-against-ai-systems\\\/\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/attacks-against-ai-systems\\\/\",\"name\":\"Attacks Against AI Systems: The Taxonomy, Organised\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/attacks-against-ai-systems\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/attacks-against-ai-systems\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Attacks-Against-AI-Systems-blog-banner.png\",\"datePublished\":\"2026-09-17T12:30:29+00:00\",\"dateModified\":\"2026-09-17T12:30:31+00:00\",\"description\":\"Attacks against AI now have three OWASP taxonomies. See the model, agent, and tool layers explained, the incidents behind them, and how the chains connect.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/attacks-against-ai-systems\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/threatcop.com\\\/blog\\\/attacks-against-ai-systems\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/attacks-against-ai-systems\\\/#primaryimage\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Attacks-Against-AI-Systems-blog-banner.png\",\"contentUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Attacks-Against-AI-Systems-blog-banner.png\",\"width\":1280,\"height\":720,\"caption\":\"Threatcop blog banner reading Attacks Against AI Systems, The Three Lists That Organise Them, over an abstract stacked bar graphic on a dark navy background\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/attacks-against-ai-systems\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Attacks Against AI Systems: The Three Lists That Organise Them\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/\",\"name\":\"Threatcop\",\"description\":\"Cybersecurity Blogs, News, Updates, and Articles\",\"publisher\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#organization\",\"name\":\"Threatcop\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/threatcop-logo-black-1.png\",\"contentUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/threatcop-logo-black-1.png\",\"width\":432,\"height\":102,\"caption\":\"Threatcop\"},\"image\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/people\\\/Threatcop\\\/100083109892339\\\/\",\"https:\\\/\\\/x.com\\\/threatcop\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/threatcop\\\/\",\"https:\\\/\\\/www.instagram.com\\\/threatcop_official\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#\\\/schema\\\/person\\\/1dcc018f2b81f296caf1a9e6cdd7c355\",\"name\":\"Sushant Sharma\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/avatar_user_28_1789477775-96x96.png\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/avatar_user_28_1789477775-96x96.png\",\"contentUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/avatar_user_28_1789477775-96x96.png\",\"caption\":\"Sushant Sharma\"},\"description\":\"Sushant Kumar is the AVP \u2013 Technology at Threatcop, bringing over a decade of experience in technology leadership and product development. He has worked across technology-driven organizations, including Paytm, and focuses on building scalable solutions that address evolving business and cybersecurity challenges. His areas of interest include cybersecurity technology, AI-driven security, product innovation, and enterprise technology. He is passionate about using technology to solve complex security challenges.\",\"sameAs\":[\"https:\\\/\\\/threatcop.com\\\/\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Attacks Against AI Systems: The Taxonomy, Organised","description":"Attacks against AI now have three OWASP taxonomies. See the model, agent, and tool layers explained, the incidents behind them, and how the chains connect.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/threatcop.com\/blog\/attacks-against-ai-systems\/","og_locale":"en_US","og_type":"article","og_title":"Attacks Against AI Systems: The Taxonomy, Organised","og_description":"Attacks against AI now have three OWASP taxonomies. See the model, agent, and tool layers explained, the incidents behind them, and how the chains connect.","og_url":"https:\/\/threatcop.com\/blog\/attacks-against-ai-systems\/","og_site_name":"Threatcop","article_publisher":"https:\/\/www.facebook.com\/people\/Threatcop\/100083109892339\/","article_published_time":"2026-09-17T12:30:29+00:00","article_modified_time":"2026-09-17T12:30:31+00:00","og_image":[{"width":1280,"height":720,"url":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Attacks-Against-AI-Systems-blog-banner.png","type":"image\/png"}],"author":"Sushant Sharma","twitter_card":"summary_large_image","twitter_creator":"@threatcop","twitter_site":"@threatcop","twitter_misc":{"Written by":"Sushant Sharma","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/threatcop.com\/blog\/attacks-against-ai-systems\/#article","isPartOf":{"@id":"https:\/\/threatcop.com\/blog\/attacks-against-ai-systems\/"},"author":{"name":"Sushant Sharma","@id":"https:\/\/threatcop.com\/blog\/#\/schema\/person\/1dcc018f2b81f296caf1a9e6cdd7c355"},"headline":"Attacks Against AI Systems: The Three Lists That Organise Them","datePublished":"2026-09-17T12:30:29+00:00","dateModified":"2026-09-17T12:30:31+00:00","mainEntityOfPage":{"@id":"https:\/\/threatcop.com\/blog\/attacks-against-ai-systems\/"},"wordCount":1842,"commentCount":0,"publisher":{"@id":"https:\/\/threatcop.com\/blog\/#organization"},"image":{"@id":"https:\/\/threatcop.com\/blog\/attacks-against-ai-systems\/#primaryimage"},"thumbnailUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Attacks-Against-AI-Systems-blog-banner.png","articleSection":["AI &amp; Cybersecurity"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/threatcop.com\/blog\/attacks-against-ai-systems\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/threatcop.com\/blog\/attacks-against-ai-systems\/","url":"https:\/\/threatcop.com\/blog\/attacks-against-ai-systems\/","name":"Attacks Against AI Systems: The Taxonomy, Organised","isPartOf":{"@id":"https:\/\/threatcop.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/threatcop.com\/blog\/attacks-against-ai-systems\/#primaryimage"},"image":{"@id":"https:\/\/threatcop.com\/blog\/attacks-against-ai-systems\/#primaryimage"},"thumbnailUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Attacks-Against-AI-Systems-blog-banner.png","datePublished":"2026-09-17T12:30:29+00:00","dateModified":"2026-09-17T12:30:31+00:00","description":"Attacks against AI now have three OWASP taxonomies. See the model, agent, and tool layers explained, the incidents behind them, and how the chains connect.","breadcrumb":{"@id":"https:\/\/threatcop.com\/blog\/attacks-against-ai-systems\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/threatcop.com\/blog\/attacks-against-ai-systems\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/threatcop.com\/blog\/attacks-against-ai-systems\/#primaryimage","url":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Attacks-Against-AI-Systems-blog-banner.png","contentUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Attacks-Against-AI-Systems-blog-banner.png","width":1280,"height":720,"caption":"Threatcop blog banner reading Attacks Against AI Systems, The Three Lists That Organise Them, over an abstract stacked bar graphic on a dark navy background"},{"@type":"BreadcrumbList","@id":"https:\/\/threatcop.com\/blog\/attacks-against-ai-systems\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/threatcop.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Attacks Against AI Systems: The Three Lists That Organise Them"}]},{"@type":"WebSite","@id":"https:\/\/threatcop.com\/blog\/#website","url":"https:\/\/threatcop.com\/blog\/","name":"Threatcop","description":"Cybersecurity Blogs, News, Updates, and Articles","publisher":{"@id":"https:\/\/threatcop.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/threatcop.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/threatcop.com\/blog\/#organization","name":"Threatcop","url":"https:\/\/threatcop.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/threatcop.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/08\/threatcop-logo-black-1.png","contentUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/08\/threatcop-logo-black-1.png","width":432,"height":102,"caption":"Threatcop"},"image":{"@id":"https:\/\/threatcop.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/people\/Threatcop\/100083109892339\/","https:\/\/x.com\/threatcop","https:\/\/www.linkedin.com\/company\/threatcop\/","https:\/\/www.instagram.com\/threatcop_official\/"]},{"@type":"Person","@id":"https:\/\/threatcop.com\/blog\/#\/schema\/person\/1dcc018f2b81f296caf1a9e6cdd7c355","name":"Sushant Sharma","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/avatar_user_28_1789477775-96x96.png","url":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/avatar_user_28_1789477775-96x96.png","contentUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/avatar_user_28_1789477775-96x96.png","caption":"Sushant Sharma"},"description":"Sushant Kumar is the AVP \u2013 Technology at Threatcop, bringing over a decade of experience in technology leadership and product development. He has worked across technology-driven organizations, including Paytm, and focuses on building scalable solutions that address evolving business and cybersecurity challenges. His areas of interest include cybersecurity technology, AI-driven security, product innovation, and enterprise technology. He is passionate about using technology to solve complex security challenges.","sameAs":["https:\/\/threatcop.com\/"]}]}},"_links":{"self":[{"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/posts\/15370","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/users\/28"}],"replies":[{"embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/comments?post=15370"}],"version-history":[{"count":1,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/posts\/15370\/revisions"}],"predecessor-version":[{"id":15401,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/posts\/15370\/revisions\/15401"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/media\/15385"}],"wp:attachment":[{"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/media?parent=15370"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/categories?post=15370"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/tags?post=15370"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}