With the widespread deployment of generative and agentic AI systems across industries, the risks they introduce have become immediate, material, and in many cases, poorly understood. Two recent works frame the challenge from different but complementary angles: the OWASP GenAI Incident Response Guide (2025) and the white paper Agentic AI Threats: A MITRE ATT&CK Analysis (2025). Taken together, these perspectives provide a blueprint for organizations that must both defend against AI-specific incidents today and anticipate the rise of autonomous AI adversaries tomorrow.

AI Incidents: The Defensive Baseline

OWASP’s GenAI Incident Response Guide addresses a growing operational gap. Security teams that have long relied on established frameworks like NIST or ISO now face an influx of novel incident types that do not fit neatly into traditional categories.

The guide outlines AI-specific failure modes:

  • Hallucinations that mislead customers or staff.

  • Prompt injection attacks that hijack context windows.

  • Model poisoning that alters decision-making integrity.

  • Excessive autonomy, where AI agents act without human oversight.

By mapping these risks to layers of the AI stack (model, implementation, system, runtime), OWASP provides responders with practical diagnostic criteria. Anomalous outputs, model drift, or unauthorized API behavior are treated not as software bugs but as incident triggers requiring their own containment, eradication, and recovery processes.

The guide also emphasizes governance. AI risks should appear in the enterprise risk register alongside cyber, operational, and compliance risks. Risk owners must be explicitly assigned, controls documented, and monitoring tied to executive dashboards. In other words, AI incident response is not an isolated security function but a board-relevant governance issue.

Agentic AI as Adversary: The Next Frontier

Where OWASP prepares us to manage incidents, the MITRE ATT&CK–based Agentic AI Threats analysis asks a darker question: what happens when the AI itself becomes the attacker?

Agentic AI is defined as a system capable of persistent goal pursuit, adaptive reasoning, and chaining actions across environments. Unlike static automation, these systems maintain long-term objectives and adjust their methods based on real-time feedback. Applied maliciously, this creates a new class of adversary that can sustain multi-vector, autonomous campaigns.

The paper maps these capabilities across the ATT&CK kill chain:

  • Reconnaissance: perpetual OSINT and API scanning, blending into normal traffic.

  • Resource Development: registering domains, building synthetic identities, and generating phishing kits dynamically.

  • Initial Access: adaptive phishing and exploit mutation that improve with every attempt.

  • Execution and Persistence: autonomous script modification, continuous probing, and redundant footholds.

  • Lateral Movement and Impact: multi-threaded operations that force defenders to fight on multiple fronts simultaneously.

The implication is sobering: much of this is not speculative. AI systems today can already automate reconnaissance, phishing personalization, and exploit generation. What remains manual, such as complex privilege escalation or stealthy lateral movement, is narrowing rapidly.

Bringing the Views Together

The value of comparing these two works lies in how they complement each other.

  • OWASP provides the playbook for defending AI systems as enterprise assets. It gives incident responders the tools to detect, contain, and learn from failures that emerge from the AI stack itself.

  • MITRE ATT&CK analysis projects the trajectory of AI as an offensive weapon, showing how agentic adversaries will exploit the same stack layers defenders are learning to secure.

Taken together, they suggest a layered defense strategy:

  1. Operational Readiness: Incorporate OWASP diagnostic criteria into SOC workflows and risk registers today. Ensure telemetry captures prompt-level anomalies and model drift.

  2. Adversary Simulation: Use the MITRE ATT&CK mapping to run red-team exercises with AI-driven adversary emulations. Train defenders to respond not just to incidents of failure, but to autonomous adversarial behavior.

  3. Governance Integration: Treat AI risks as enterprise-wide strategic risks, assigning accountability across security, compliance, legal, and business owners.

  4. Adaptive Defense: Shift security architectures toward real-time behavioral analysis and deception technologies that can counter continuously learning adversaries.

  5. Continuous Feedback Loop: Feed lessons from AI incidents (OWASP) into threat modeling (MITRE), creating a cycle where operational data informs strategic foresight.

Strategic Implications

The convergence of these perspectives signals a shift: AI is both a fragile asset to defend and a powerful adversary to anticipate. Organizations that focus only on present-day incidents will be blindsided by the coming wave of autonomous AI attackers. Conversely, those who only theorize about future adversaries without strengthening present-day incident response will fail to contain immediate risks.

The synthesis of OWASP and MITRE guidance creates a full-stack AI defense model:

  • Defend the AI you deploy.

  • Anticipate the AI that will attack.

  • Integrate both into enterprise governance and operational assurance.

This dual lens transforms AI risk from a siloed technical concern into a strategic imperative for organizational resilience and trust.

Conclusion

AI is rewriting the playbook for both attackers and defenders. The OWASP GenAI Incident Response Guide grounds security teams in today’s operational challenges. The MITRE ATT&CK analysis of Agentic AI projects the capabilities of tomorrow’s adversaries. Security leaders who integrate both perspectives will be better positioned to navigate a landscape where AI is not just a tool we use, but an actor we must defend against.