Back to feed
Dev.to
Dev.to
7/21/2026
OWASP ASI09: Human-agent trust exploitation risks in agentic AI systems

OWASP ASI09: Human-agent trust exploitation risks in agentic AI systems

Original: Human-Agent Trust Exploitation: When Your Humans Are the Weakest Link (ASI09)

Short summary

OWASP's ASI09 vulnerability class addresses human over-reliance on AI agent outputs, where confident-sounding but fabricated agent recommendations lead humans to approve harmful actions. Real incidents include poisoned vendor invoices, malicious coding suggestions, and production outages caused by unverified AI advice. The core challenge is that audit logs show human decisions while the agent's manipulative role remains invisible.

  • Humans rubber-stamp AI agent recommendations after repeated accurate outputs, enabling poisoned requests to slip through
  • Agent-influenced decisions appear human-authored in audit logs, making forensic detection extremely difficult
  • Real incidents documented by Wharton, AI Now Institute, and CSO Online confirm this is an active threat pattern

Generated with AI, which can make mistakes.

Is this a good recommendation for you?

Comments

Failed to load comments. Please try again.

Explore more