How AI governance works
What is the OWASP Top 10 for LLM applications?
Short answerThe OWASP Top 10 for LLM Applications is a free list of the ten most serious security risks in software built on large language models, published by the OWASP GenAI Security Project. The current edition is the 2026 list, published August 4, 2026: Prompt Injection stays first, Excessive Agency climbs to third, and System Prompt Leakage becomes Hidden Context Exposure. The 2025 list, which runs from LLM01 Prompt Injection to LLM10 Unbounded Consumption, is still widely cited, and a companion Top 10 for Agentic Applications covers AI agents that act on their own.
OWASP is the Open Worldwide Application Security Project, the nonprofit behind the web application Top 10. Its GenAI Security Project maintains the LLM list, and each entry gives a definition, examples, prevention steps, and attack scenarios. On October 8, 2026, the list page at genai.owasp.org still showed the 2025 entries while the OWASP project page carried the 2026 release, so both numberings circulate.
What are the OWASP top 10 risks for LLM applications?
| Risk (2026) | What it means | Example | Control that addresses it |
|---|---|---|---|
| LLM01 Prompt Injection | Anything the model reads (a prompt, web page, file, image, tool output, or memory) changes its behavior in ways the builder never intended. | An attacker tells a support chatbot to ignore its guidelines, query private data, and send emails. | Keep credentials and state changes in application code, validate every response, label outside content by source, and require human confirmation for irreversible actions. |
| LLM02 Sensitive Information Disclosure | The system exposes confidential or regulated data through answers, tool calls, logs, embeddings, or reasoning traces. | Crafted prompts make a production model repeat memorized personal data and live credentials. | Send the model only the fields a task needs, check authorization before retrieval, and keep secrets out of system prompts. |
| LLM03 Excessive Agency | The model has more tools, permissions, or autonomy than its job needs. | An email assistant built to read mail can also send it, and an incoming message tricks it into forwarding sensitive data. | Minimize tools and permissions, run tools as the user, and require approval for high-impact actions. |
| LLM04 Supply Chain | Third-party models, adapters, datasets, packages, or serving platforms are tampered with or vulnerable. | In December 2022 a malicious package on PyPI shadowed a PyTorch nightly dependency and exfiltrated data. | Vet suppliers, keep a signed AI bill of materials, and verify model signatures and file hashes. |
| LLM05 Data and Model Poisoning | Someone manipulates training, fine-tuning, retrieval, or model files to plant harmful behavior or backdoors. | Manipulated documents planted in an internal knowledge base surface in answers and steer business decisions. | Track data lineage, validate incoming data, version datasets, and red team for backdoors. |
| LLM06 Unbounded Consumption | Uncontrolled use takes the service down, runs up the bill (denial of wallet), or lets someone clone the model. | An oversized input exhausts memory and CPU and slows or crashes the service. | Set rate limits and input size checks, hard spending caps, and circuit breakers for agents. |
| LLM07 Misinformation | Wrong, incomplete, or unsupported output looks credible and a person, workflow, or agent acts on it. | A coding assistant recommends a nonexistent package that an attacker has already registered with malicious code. | Ground claims in current sources, verify before acting, and require approval for high-impact actions. |
| LLM08 Hidden Context Exposure | Attackers extract or infer the hidden instructions and context behind an app. Formerly System Prompt Leakage. | A system prompt holds a tool's login credentials, and an attacker pulls them out and reuses them. | Keep sensitive data out of hidden context, use deterministic guardrails, and enforce authorization outside the model. |
| LLM09 Vector and Embedding Weaknesses | The similarity search behind RAG, agent memory, and semantic caches lets attackers plant content or reach data. | An attacker publishes forum posts built to surface when staff ask the company assistant about revenue. | Check permissions at retrieval, authenticate sources, and monitor ingest and retrieval. |
| LLM10 Improper Output Handling | Model output reaches other systems without validation or encoding. | A chatbot passes unchecked output to an admin tool, which shuts down. | Treat model output as untrusted, encode it for its destination, and use parameterized queries. |
What changed from the OWASP LLM top 10 2025?
For the first time, OWASP tested its practitioner vote against 6,639 classified real-world incidents. The vote carries three-quarters of the weight and the incidents one quarter. Prompt injection would drop out of the top ten on incident counts alone; the project leads kept it first because teams defend against it hard and every model that reads untrusted input exposes it.
| 2025 entry | 2026 position |
|---|---|
| LLM01 Prompt Injection | LLM01, held |
| LLM02 Sensitive Information Disclosure | LLM02, held |
| LLM03 Supply Chain | LLM04 |
| LLM04 Data and Model Poisoning | LLM05 |
| LLM05 Improper Output Handling | LLM10, the largest fall |
| LLM06 Excessive Agency | LLM03, the most consequential rise |
| LLM07 System Prompt Leakage | LLM08, renamed Hidden Context Exposure |
| LLM08 Vector and Embedding Weaknesses | LLM09 |
| LLM09 Misinformation | LLM07 |
| LLM10 Unbounded Consumption | LLM06, up four places |
Who is the OWASP LLM top 10 for?
The list serves teams that build, deploy, or secure applications on an LLM: developers, security engineers, and architects. The 2026 preface draws the boundary plainly. This list covers the model as a component inside your application; once the model calls tools, keeps memory, and sets actions in motion, pair it with the Agentic Top 10. Buyers use both lists as vendor questions.
What should a company that only uses ChatGPT take from it?
Most of the list describes the vendor's job; ask the vendor how it handles supply chain, poisoning, retrieval, output, and consumption controls. Four entries apply to how your own people work:
- Sensitive information disclosure (LLM02): decide what staff are allowed to paste in, write it down, and back it with a control. See where your data goes.
- Misinformation (LLM07): check figures, citations, and code before they leave the building. OWASP defines the core risk as wrong output that gets trusted and acted on.
- Prompt injection and excessive agency (LLM01 and LLM03): when an assistant reads web pages, files, or email, or connects to your mailbox and drive, text inside that content can steer it. Connect only what the task needs and review proposed actions before they run.
Is there an OWASP top 10 for AI agents?
Yes. The OWASP Top 10 for Agentic Applications for 2026 was published on December 9, 2025, for AI agents that plan, call tools, and act across several steps. It works alongside the LLM list; OWASP notes, for example, that its tool misuse entry builds on Excessive Agency for multi-step workflows. The ten entries are:
- ASI01 Agent Goal Hijack
- ASI02 Tool Misuse and Exploitation
- ASI03 Identity and Privilege Abuse
- ASI04 Agentic Supply Chain Vulnerabilities
- ASI05 Unexpected Code Execution (RCE)
- ASI06 Memory and Context Poisoning
- ASI07 Insecure Inter-Agent Communication
- ASI08 Cascading Failures
- ASI09 Human-Agent Trust Exploitation
- ASI10 Rogue Agents
The agentic list introduces least agency: give an agent only the autonomy a bounded task requires, since unneeded autonomy widens the attack surface. It also calls strong observability non-negotiable: clear visibility into what agents do, why, and which tools they invoke. See what you can see while your AI is running.
How does the OWASP LLM top 10 map to NIST AI RMF and MITRE ATLAS?
The 2026 release publishes its own mappings to nine frameworks. The NIST AI Risk Management Framework (AI RMF 1.0, January 2023, voluntary) organizes risk work into Govern, Map, Measure, and Manage; its Generative AI Profile (NIST AI 600-1, July 2024) names twelve generative AI risks. MITRE ATLAS catalogs attacker tactics and techniques against AI systems.
| OWASP 2026 entry | NIST AI 600-1 risk (primary) | MITRE ATLAS tactic (primary) |
|---|---|---|
| LLM01 Prompt Injection | Information Security | Initial Access, Execution, Persistence, Defense Evasion, Exfiltration |
| LLM02 Sensitive Information Disclosure | Data Privacy, Information Security | Exfiltration |
| LLM03 Excessive Agency | Information Security | Execution, Impact |
| LLM04 Supply Chain | Value Chain and Component Integration, Information Security | Initial Access |
| LLM05 Data and Model Poisoning | Information Integrity, Value Chain and Component Integration, Information Security | Resource Development, Persistence, Impact |
| LLM06 Unbounded Consumption | Information Security | Impact, Exfiltration |
| LLM07 Misinformation | Information Integrity, Confabulation, Human-AI Configuration | Impact |
| LLM08 Hidden Context Exposure | Information Security | Discovery, Exfiltration |
| LLM09 Vector and Embedding Weaknesses | Data Privacy, Information Security, Information Integrity | Persistence, Exfiltration |
| LLM10 Improper Output Handling | Information Security | Execution |
How do you put the OWASP LLM top 10 into practice?
- Inventory every LLM application and agent, then mark which LLM and agentic entries apply to each.
- Enforce controls at runtime, outside the model. OWASP's advice is to build for the day the model is fooled, so checks, tool permissions, and approvals run on every request. See what runtime enforcement looks like.
- Log every request and tool call, and red team on a schedule, before release and after each model change.
Frequently asked questions
- What is the OWASP Top 10 for LLM applications?
- It is a free list from the OWASP GenAI Security Project naming the ten most serious security risks in applications built on large language models, each with examples and prevention steps. The current edition is the 2026 list, published August 4, 2026.
- What are the OWASP LLM top 10 risks for 2025?
- LLM01 Prompt Injection, LLM02 Sensitive Information Disclosure, LLM03 Supply Chain, LLM04 Data and Model Poisoning, LLM05 Improper Output Handling, LLM06 Excessive Agency, LLM07 System Prompt Leakage, LLM08 Vector and Embedding Weaknesses, LLM09 Misinformation, and LLM10 Unbounded Consumption.
- What changed in the 2026 OWASP LLM top 10?
- Excessive Agency rose from sixth to third, Unbounded Consumption rose four places, Improper Output Handling fell from fifth to tenth, and System Prompt Leakage became Hidden Context Exposure. The ranking now weighs a practitioner vote at 75% and a record of real incidents at 25%.
- What is the number one risk in the OWASP LLM top 10?
- Prompt injection (LLM01) in both the 2025 and 2026 lists. It covers any input the model reads, including web pages, files, images, audio, tool output, and memory, that changes the model's behavior in unintended ways.
- Where can I get the OWASP top 10 for LLM applications PDF?
- The 2026 release is free from the OWASP GenAI Security Project at genai.owasp.org, and its full text is in the project's public GitHub repository. Use those as the source of record, since copies elsewhere go out of date.
- Is there an OWASP AI top 10 for agents?
- Yes. The OWASP Top 10 for Agentic Applications for 2026, published December 9, 2025, covers agents that plan and call tools, from ASI01 Agent Goal Hijack to ASI10 Rogue Agents. OWASP says to read it alongside the LLM list once a model starts acting on its own.
- What are LLM security best practices?
- Treat all model input and output as untrusted, give models and agents only the permissions a task needs, enforce controls outside the model on every request, log every request and tool call, and red team before release and after each model change.
Sources
- OWASP Foundation, OWASP Top 10 for Large Language Model Applications (project page: current release published August 4, 2026). Read October 8, 2026.
- OWASP GenAI Security Project, GenAI LLM Top 10 2026, final entries LLM01 to LLM10 and preface (GitHub). Read October 8, 2026.
- OWASP GenAI Security Project, Appendix A: Related Framework Mappings (2026 release). Read October 8, 2026.
- OWASP GenAI Security Project, OWASP GenAI LLM Top 10 2026 (download page). Read October 8, 2026.
- OWASP GenAI Security Project, 2025 Top 10 Risk and Mitigations for LLMs and Gen AI Apps. Read October 8, 2026.
- OWASP GenAI Security Project, OWASP Top 10 for Agentic Applications for 2026 (December 9, 2025). Read October 8, 2026.
- NIST, AI Risk Management Framework. Read October 8, 2026.
- NIST, AI 600-1, Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (July 2024). Read October 8, 2026.
- MITRE, ATLAS data (tactics and techniques). Read October 8, 2026.
Reviewed