TL;DR: OWASP GenAI Project hosts a half-day summit on June 4, 2026, in London, covering agentic AI risks and European regulatory strategy for CISOs and AI
The OWASP GenAI Security Project held a half-day summit on June 4, 2026, at ExCeL London, during Infosecurity Europe. The event drew global project leaders, security practitioners, and regulatory experts to share research and frameworks for securing GenAI and agentic systems. For engineering leaders at small and mid-sized European companies, this summit matters because it marks the formalization of agentic security guidance that will influence how AI systems are built, audited, and procured across the EU. The growing body of OWASP guidance may produce controls that directly affect how AI outputs are sanitized and how security baselines are set, making early awareness a competitive necessity.
Inside the Summit: What Was Announced
According to the OWASP GenAI Security Project page at genai.owasp.org, the summit offered first access to the project’s latest research. Attendees explored emerging security risks specific to agentic AI systems, a class of AI that can take autonomous actions and is increasingly deployed in business operations. The agenda covered field-tested best practices for building secure, compliant, and resilient AI at scale.
A key track focused on European regulatory developments and how they are shaping AI security strategy. This aligns with growing enforcement of the EU AI Act and related frameworks, which demand rigorous risk management for high-risk AI applications. The summit featured organisations that have applied OWASP GenAI best practices in production, providing concrete case studies on reducing exposure to prompt injection, data leakage, and unauthorized agent actions.
The in-person format at Infosecurity Europe enabled direct engagement between attendees and project leaders. Engineering leaders gained insight into which controls are being considered for formal inclusion in OWASP guidance, giving them a head start on aligning internal policies with emerging standards.
Why Agentic Security Guidance Matters for European Engineering Teams
Agentic AI systems introduce threats that traditional application security does not cover. An AI agent that can browse the web, execute API calls, or trigger downstream workflows requires a distinct threat model. OWASP’s move to formalize guidance signals that agentic security will soon be a baseline expectation, not an optional add-on.
For small and mid-sized engineering teams, adopting these controls early offers a pragmatic advantage. European regulators are explicitly referencing industry standards when evaluating compliance, and OWASP is a recognised authority in application security. Aligning with OWASP GenAI guidelines can demonstrate due diligence, simplify audits, and reduce the risk of enforcement actions.
Furthermore, procurement requirements are shifting. Clients and partners are beginning to ask about AI security posture. Having agentic-specific security measures in place-drawn from a formal OWASP framework-can serve as a differentiator in RFPs and security questionnaires.
Operational Takeaways for CISOs and Compliance Leaders
The summit made clear that waiting for finalised regulation is not a strategy. CISOs and compliance executives should consider immediate steps:
- Monitor OWASP GenAI outputs: The project is the most visible effort to codify agentic security practices. Its mailing list and GitHub repository are primary sources for emerging controls.
- Assess your agentic attack surface: Inventory AI agents in use, map their permissions and data flows, and test for common agentic weaknesses such as indirect prompt injection or goal hijacking.
- Integrate guidance into SDLC: Incorporate OWASP GenAI checklists into design reviews, code reviews, and penetration testing. Even preliminary guidance can inform threat modeling.
- Prepare for regulatory alignment: The EU AI Act requires risk classification and conformity assessments. Using OWASP benchmarks can help structure these processes and demonstrate technical rigour to notified bodies.
Attendees at the summit heard directly from project leaders, gaining early insight into which areas the guidance will prioritise. Engaging with the community now allows teams to influence the guidance while it is still being shaped.
What Comes Next for OWASP GenAI
The summit is part of a broader push by OWASP to address generative AI and agentic risks. Expect additional resources, including an updated Top Ten list for agentic AI, dedicated testing frameworks, and reference architectures for secure agent deployment.
The project’s leader indicated that the guidance will be modular, allowing teams to adopt controls incrementally. This is particularly useful for smaller organisations that may not have dedicated AI security teams.
Future events will likely expand on the London summit’s themes, with regional workshops planned to gather European-specific feedback. Engineering leaders should track the OWASP GenAI events page and participate in upcoming calls for contributors.
Frequently Asked Questions
Q: What is the OWASP GenAI Security Project?
It is an OWASP initiative that develops open-source resources, frameworks, and best practices for securing generative AI and agentic systems. The project involves volunteer experts from industry and academia.
Q: Who should attend future OWASP GenAI summits?
The summits are designed for CISOs, security architects, AI product leaders, compliance executives, and regulators. Anyone responsible for AI risk management will gain practical value.
Q: How does agentic security differ from standard AI security?
Agentic security focuses on the additional attack surfaces and failure modes introduced when AI systems can take actions independently, such as executing tool calls or managing workflows.
Q: Where can I find the materials from the summit?
Selected slides and recordings are typically published on the OWASP GenAI Security Project website at genai.owasp.org. Attendees may receive early access to draft guidance documents.