Not sure where to start? Answer 3 questions and get a tailored compliance action plan.
What applies to me? →OWASP Top 10 for Large Language Model Applications
Issued by
OWASP Foundation
- September 30, 2026 · Correction — Updated the risk list to the 2025 edition; the entry previously described the 2023 list. (Cody Maxwell)
OWASP's Top 10 for LLM Applications lists the most critical security risks in applications built on large language models. The 2025 edition covers risks such as prompt injection, sensitive information disclosure, supply chain weaknesses, data and model poisoning, and excessive agency. Development and security teams use it to prioritize safeguards.
Applies To
Overview
The OWASP (Open Worldwide Application Security Project) Top 10 for LLM Applications is a community-built security list. It names the most critical weaknesses in systems built on large language models (LLMs), the AI behind chatbots and writing assistants. It was first published in 2023, and the current edition is the 2025 list. The 2025 list covers prompt injection (inputs that override the model's instructions), sensitive information disclosure, and supply chain weaknesses in third-party models and components. It also covers data and model poisoning (tampering with what a model learns from) and improper output handling (trusting model output without checking it). Excessive agency covers AI given more power to act than it needs. System prompt leakage covers exposing the hidden instructions behind an application. Vector and embedding weaknesses cover flaws in the document stores that feed retrieval systems. Misinformation covers false output that people rely on, and unbounded consumption covers runaway usage that drives up cost or knocks a service over. Each entry describes the risk, example attacks, and ways to reduce it. The list is meant to sit alongside existing application security practice, and it matters most for organizations deploying AI agents that can take actions on their own.
Key Requirements
- •Implement input validation and output sanitization for all LLM interactions
- •Establish access controls limiting what actions LLM-powered systems can take
- •Monitor for prompt injection and anomalous model behavior in production
- •Apply least-privilege principles to AI agent permissions
- •Conduct supply chain due diligence on third-party models and plugins
What Your Organization Must Do
- →Assign the security team lead to map all LLM-powered applications against each of the OWASP Top 10 LLM categories and document findings in a risk register by the end of the current quarter.
- →Require development teams to check what goes into and comes out of every LLM integration (input validation and output sanitization) before deployment, using code review checkpoints to verify compliance.
- →Enforce least-privilege permissions (only the access needed for the task) for all AI agents and plugins, reviewed at each release cycle.
- →Establish automated monitoring in production environments to detect prompt injection attempts and unusual model outputs, with alerts routed to the security operations center for triage within 24 hours.
- →Conduct supply chain due diligence on all third-party models, APIs (connections to outside software services), and plugins before adoption, including a documented review of their origin, update history, and known vulnerabilities before go-live approval.
- →Schedule a recurring review of LLM security controls at least annually or upon any major change to the model or system design, to incorporate updates from future OWASP Top 10 revisions.
Playbook Guidance
Step-by-step implementation guidance for compliance teams.
Governance Controls
Operational controls that implement requirements from this regulation.
Frequently Asked Questions
- Is the OWASP LLM Top 10 a mandatory compliance requirement or a voluntary framework?
- It is voluntary. The OWASP LLM Top 10 is a community-driven guidance framework with no regulatory enforcement mechanism. However, it is frequently referenced in procurement requirements, security audits, and regulatory guidance, so alignment is increasingly expected in enterprise and regulated environments.
- What is the difference between the 2023 and 2025 versions of the OWASP LLM Top 10?
- The 2025 list adds system prompt leakage, vector and embedding weaknesses, and misinformation. Unbounded consumption replaces model denial of service with a broader risk that includes runaway costs. Excessive agency was expanded for AI agents, and insecure plugin design and model theft no longer have their own entries.
- How does prompt injection in the OWASP LLM Top 10 differ from traditional SQL injection?
- Prompt injection manipulates natural language inputs to override an LLM's intended behavior or system instructions, rather than exploiting a structured query parser. It is harder to detect with conventional input validation because the attack surface is unstructured text rather than a defined syntax.
- Which OWASP LLM Top 10 risk is most relevant for companies deploying AI agents with tool access?
- Excessive agency is the most directly relevant risk. It covers scenarios where an LLM-powered agent has permissions or capabilities beyond what its task requires, increasing the blast radius of a compromised or manipulated model. Least-privilege principles and scoped tool access are the primary mitigations.
- Does the OWASP LLM Top 10 apply to companies using third-party LLM APIs rather than self-hosted models?
- Yes, several risks apply directly to organizations that use third-party LLM services. These include supply chain weaknesses, sensitive information disclosure, and improper output handling. You do not need to own the model for the list to be relevant.
- How should compliance teams use the OWASP LLM Top 10 alongside existing frameworks like NIST AI RMF or ISO 42001?
- The OWASP LLM Top 10 is a technical security reference that complements higher-level risk and governance frameworks. It is best used to operationalize controls within the risk treatment and testing phases of NIST AI RMF or ISO 42001 implementation, particularly for application-layer security.
