Eliza Ward: Hey — genuinely curious what your read is on the OWASP thing.
Brian Reed: The 2026 list? I read it twice and I'm still — let me see — I'm not sure the results cohere.
Eliza Ward: Published August 4th by the OWASP GenAI Security Project. Third edition overall, first one to actually incorporate real-world incident data.
Brian Reed: And the data moved Misinformation — from around ninth up to seventh.
Eliza Ward: That's LLM07 now. Two spots up.
Brian Reed: Which, fine — you add incident data, some things move. But Prompt Injection is still number one, for the third consecutive year, and from what I can tell the incident count for Prompt Injection is... not high.
Eliza Ward: Hold on — so the narrative is 'we finally have real data driving the list,' and the data moved Misinformation up two places, but it didn't touch the number one slot at all?
Brian Reed: That's what puzzles me. Both outcomes came from the same methodology. And they're pointing in completely different directions about how much incidents actually matter.
Eliza Ward: Right — but the part that breaks the clean version is that it wasn't hidden. They said it explicitly.
Brian Reed: OWASP looked at 7,714 incidents — Invicti reported that number — and then just... decided that 75% of the final ranking goes to expert consensus, 25% to incident data. And they said it out loud. Help Net Security quoted the project leads directly: 'one noisy year of data does not get to overturn the judgment of the people doing the work.'
Eliza Ward: They published that quote.
Brian Reed: Publicly. So here's the plain version: think of a hiring committee. They interview candidates — real interviews, real data — but three-quarters of the final decision belongs to the senior partners' read on fit. The interviews happen, they count, they can shift things at the margins. Misinformation moved up two spots. But they cannot flip the table on whoever the partners already believe is the best candidate. That's Prompt Injection at number one, third year running, low incident count and all.
Eliza Ward: Wait — so of the 7,714 total, only 6,639 were actually classifiable. That's already — I mean, before you even get to the 75/25 math, over a thousand incidents didn't make it into the count at all.
Brian Reed: Right, and that's — yeah, that's a real gap. But I'd actually push the other direction: even with 6,639 usable incidents, experts still held 75% of the weight. The data wasn't overruled because it was thin. It was structurally capped before anyone looked at the results.
Eliza Ward: Which makes the Misinformation move more interesting, not less. Two places on 25% of the weight? That's actually a pretty strong signal from the incident side.
Brian Reed: Or — and this is me guessing — experts were already movable on Misinformation. It costs less institutionally to say 'we underestimated that one' than to say Prompt Injection maybe doesn't deserve the top slot for a third straight year.
Eliza Ward: That's not confirmed. But the 75/25 split being a deliberate institutional call — that part is. They chose it and they said so.
Brian Reed: But that asymmetry is exactly the take that's getting walked past. Every headline I've seen says 'OWASP goes empirical' — and the Prompt Injection thing just sits there breaking it.
Eliza Ward: SC Media reported it plainly — third consecutive year at number one, across 2023, 2025, and 2026. Three editions. Low incident count. Nobody's calling that weird.
Brian Reed: Right — but the 'empirical' framing can't hold both results. If the same formula pushed Misinformation up on 6,639 incidents and left Prompt Injection untouched with almost none, those aren't the same logic. That's two different outcomes wearing the same methodology as a costume.
Eliza Ward: Wait — actually that's the precise thing. It's not even that the formula broke. The formula worked exactly as written. When data agreed with experts, it confirmed the ranking. When data disagreed, experts held 75% and absorbed the hit. Prompt Injection never had to fight anything.
Brian Reed: No, I don't buy that it's neutral. Think about a hospital security team right now — they pull the 2026 list, they see Prompt Injection at number one, they reasonably assume there's an incident record backing that up. There isn't. They're triaging based on expert fear, not field frequency.
Eliza Ward: That's the real-world bite. The list doesn't say 'this ranking reflects incident volume' — it just says here's number one. And most teams won't read the methodology notes.
Brian Reed: So the 'we added data' announcement does actual work — it changes how practitioners trust the list, without the list itself changing what the data can do.
Eliza Ward: And the downstream question — I mean, this is the part that gets messier later — is whether 25% stays 25%. OWASP hasn't publicly fixed that ceiling, and Derrisa Tuscano and J. Disso are already building incident-response frameworks on top of these rankings. If the weight shifts and the methodology still isn't pinned, organizations are operationalizing a moving target.
Brian Reed: The asymmetry is the story. Not that data moved Misinformation — that the same rule produced opposite results and the list got called more empirical for it.
Eliza Ward: And that moving target is the part OWASP has left explicitly open — they haven't said whether 25% is a permanent ceiling or just where they started.
Brian Reed: Which means every year data accumulates and that number hasn't moved, someone's going to ask — wait, why not? You have three years of incidents now. Why is expert consensus still holding 75%?
Eliza Ward: Right — but the inverse is scarier. If they quietly raise it to, say, 40%, what breaks?
Brian Reed: That's — yeah, that's the actual stakes. Because 25% moved Misinformation two places in year one. Double the weight and you're not getting incremental shifts — you could flip the top five. And the Tuscano and Disso paper, the GenAI-IRF framework, it's being built downstream of rankings that were set under a methodology nobody's locked down.
Eliza Ward: Wait — they published that in 2026? While the methodology is still in flux?
Brian Reed: This year. An actual incident-response framework for generative AI systems, aligned to the OWASP LLM Top 10. So picture a security architect right now citing Tuscano and Disso in a board presentation — she's defending her triage priorities against the 2026 rankings, which are partly a function of a 75/25 split that OWASP hasn't committed to keeping.
Eliza Ward: And there's the agentic scope problem on top of that. The 2026 list expanded from chat applications to agentic and tool-using systems — so when Misinformation moved up, we actually can't isolate whether that was incident data or a category redefinition. Those are two completely different explanations.
Brian Reed: So the concrete thing to watch is — does OWASP publish the weight for the next edition before organizations have already embedded this year's rankings in their frameworks? Because that's the sequence that matters.
Eliza Ward: That's the signal. Not whether the rankings shift — whether the methodology gets fixed before the downstream frameworks calcify around it.
Brian Reed: And what settles it is actually pretty specific — the next edition either announces a new weight or it doesn't. That's the moment. Not whether Prompt Injection drops, but whether OWASP even publishes the number before organizations like the ones building on Tuscano and Disso have already printed their frameworks.
Eliza Ward: Yeah — and that threshold question, I mean, OWASP has not resolved it. That's not me inferring. They genuinely haven't said whether 25% is a floor, a ceiling, or just year one. So who decides when the data is good enough to override? That's — wait, that's not a rhetorical question. That's an actual gap in the methodology they published.
Brian Reed: No verdict yet.
Eliza Ward: None. And if Prompt Injection finally drops in 2027 — that's when we know. That's the methodology's true character becoming visible. Either the weight moved and incidents did the work, or it didn't move and the list just... confirmed itself again.
Brian Reed: Still watching.