Skip to content

The OWASP Top 10 for LLM Applications

An overview of the widely used list of the most critical security risks for applications built on language models.

Editorial team 1 min read

The OWASP Top 10 for Large Language Model Applications is a community-maintained list of key security risks for LLM-based systems. It's a practical starting point for threat modelling.

Risk Areas Covered

The list is revised periodically, but its categories include:

  • Prompt injection: manipulating model behaviour through crafted inputs.
  • Sensitive information disclosure: leaking personal data, secrets or confidential content.
  • Supply chain: compromised models, datasets, plugins or libraries.
  • Data and model poisoning: tampering with training or fine-tuning data.
  • Improper output handling: passing model output unsafely to other systems.
  • Excessive agency: giving models too many permissions or too much autonomy.
  • System prompt leakage: exposing instructions or secrets placed in prompts.
  • Vector and embedding weaknesses: risks in retrieval systems.
  • Misinformation: harmful reliance on incorrect output.
  • Unbounded consumption: resource exhaustion and runaway costs.

How to Use It

  • Walk through each risk for your application.
  • Identify which apply and how.
  • Map existing controls and gaps.
  • Prioritise fixes by impact and likelihood.

Check the Current Version

Consult the latest edition directly, as rankings and categories change between releases.

More in AI security

All AI security guides →
AI security Guide · 1 min

Introduction to AI Security

What AI security covers — attacks on models, data and AI applications — and how it differs from traditional security.

AI security 1 min read 29 Jun 2025

AI security Guide · 1 min

Jailbreaks: How They Work and How to Defend

How people try to get models to bypass their safety training, common techniques, and layered defences.

AI security 1 min read 27 Jun 2025

AI security Guide · 1 min

Indirect Prompt Injection

How attackers hide instructions in web pages, emails and documents that AI systems read, and why it's so dangerous for agents.

AI security 1 min read 26 Jun 2025

AI security Guide · 1 min

Data Poisoning Attacks

How attackers corrupt training or fine-tuning data to change model behaviour, and how to protect data pipelines.

AI security 1 min read 25 Jun 2025