OWASP Top 10 for LLM applications, explained
The OWASP Top 10 for LLM applications is the list buyers and testers use for AI features. Here is each of the ten in plain language, with what it looks like in a product and what to do about it.
The OWASP Top 10 for LLM applications (2025 edition) lists the ten most important risks in products built on large language models: prompt injection, sensitive information disclosure, supply chain, data and model poisoning, improper output handling, excessive agency, system prompt leakage, vector and embedding weaknesses, misinformation, and unbounded consumption. It is published by the OWASP GenAI Security Project and is the reference an AI security assessment is usually mapped to.
| ID | Risk | In one line |
|---|---|---|
| LLM01 | Prompt injection | Input, direct or hidden in content, changes what the model does |
| LLM02 | Sensitive information disclosure | The model reveals data it should not, including other users' |
| LLM03 | Supply chain | Models, datasets and plugins from third parties carry their own risk |
| LLM04 | Data and model poisoning | Training or fine-tuning data is manipulated to change behaviour |
| LLM05 | Improper output handling | Model output is used as code, HTML or a query without checks |
| LLM06 | Excessive agency | The model can take actions beyond what the task needs |
| LLM07 | System prompt leakage | Instructions or secrets placed in the prompt are extracted |
| LLM08 | Vector and embedding weaknesses | Retrieval stores leak across users or accept poisoned content |
| LLM09 | Misinformation | Confident wrong answers that people or systems act on |
| LLM10 | Unbounded consumption | Requests that run up cost, exhaust quota or deny service |
LLM01: prompt injection
A user, or text the model reads, contains instructions that override yours. Direct injection is typed into the chat. Indirect injection sits in a web page, email or document the model is asked to process, which makes it the dangerous one for agents. There is no complete fix; the defence is limiting what a successful injection can do. See prompt injection and how testers check for it.
LLM02: sensitive information disclosure
The model reveals personal information, confidential documents or keys. In products this usually means retrieval returns documents the user should not see, or conversation history bleeds between users. Fix it in the data layer: filter what is retrieved by the user's permissions before it reaches the model. See can a chatbot leak customer data.
LLM03: supply chain
Third-party models, fine-tunes, datasets, plugins and libraries each bring their own terms and weaknesses. Know which provider receives your data, how long they keep it and whether it trains their models.
LLM04: data and model poisoning
Relevant if you fine-tune or train on data others can influence, such as user feedback. Most apps calling a hosted model are exposed through retrieval content instead, which falls under LLM08.
LLM05: improper output handling
Model output rendered as HTML, used in a database query, passed to a shell or turned into a URL. Treat it exactly like user input: escape, validate, parameterize. This is where AI features create classic web vulnerabilities.
LLM06: excessive agency
The agent has more functions, permissions or autonomy than it needs. A support bot that can issue refunds of any size, or an assistant with a database key that can write to every table. See excessive agency and LLM red teaming.
LLM07: system prompt leakage
Assume users can read your system prompt. Put no keys, internal URLs or business rules there that would hurt if published, and never rely on the prompt for access control.
LLM08: vector and embedding weaknesses
A vector store shared across tenants without filtering returns one customer's documents in another's answer. Content added to the store by outsiders can carry injected instructions.
LLM09: misinformation
Confident wrong output that users or downstream code act on. The control is design: citations, human review for consequential answers, and never letting unverified output make decisions about people.
LLM10: unbounded consumption
No per-user limits on a paid model means anyone can run up your bill or exhaust your quota. Set token caps, request rate limits and agent loop limits. See rate limiting.
Using the list
Use it as a checklist for design and as the scope for a test. Buyers who ask how your AI feature is secured will recognise it. TrazTech's AI security assessments are mapped to it. Source: the OWASP GenAI Security Project, Top 10 for LLM applications.
Test your AI feature against the list
Describe the model, the data it reads and the tools it can call.
Get matchedCommon questions
Is the OWASP LLM Top 10 a compliance standard?
No. It is a risk list. It is used to scope tests and answer buyer questions, not audited against. ISO 42001 is the certifiable AI management standard.
Which item matters most for a typical app?
Prompt injection combined with excessive agency or disclosure. On its own an injection is a nuisance; connected to tools or other users' data it is a breach.