The OWASP Top 10 for Large Language Model Applications is a community-maintained list of key security risks for LLM-based systems. It's a practical starting point for threat modelling.
Risk Areas Covered
The list is revised periodically, but its categories include:
- Prompt injection: manipulating model behaviour through crafted inputs.
- Sensitive information disclosure: leaking personal data, secrets or confidential content.
- Supply chain: compromised models, datasets, plugins or libraries.
- Data and model poisoning: tampering with training or fine-tuning data.
- Improper output handling: passing model output unsafely to other systems.
- Excessive agency: giving models too many permissions or too much autonomy.
- System prompt leakage: exposing instructions or secrets placed in prompts.
- Vector and embedding weaknesses: risks in retrieval systems.
- Misinformation: harmful reliance on incorrect output.
- Unbounded consumption: resource exhaustion and runaway costs.
How to Use It
- Walk through each risk for your application.
- Identify which apply and how.
- Map existing controls and gaps.
- Prioritise fixes by impact and likelihood.
Check the Current Version
Consult the latest edition directly, as rankings and categories change between releases.