Application & API Security

OWASP LLM Top 10

OWASP Top 10 for LLM Applications

Community Global OWASP Since 2023

The consensus risk list for applications built on large language models: prompt injection, sensitive information disclosure, supply chain, data and model poisoning, improper output handling, excessive agency, and more.

Directly relevant wherever an LLM touches governed data: a retrieval pipeline over regulated data inherits every one of these risks, and this is the list auditors have started asking about by name.

At a glance

Category
Application & API Security
Jurisdiction
Global
Governance
OWASP
Status
2025 edition (March 2025); part of the OWASP GenAI Security Project
First released
2023

Links

Related frameworks

Other entries under Application & API Security.

See OWASP LLM Top 10 in context

Open the interactive Data Landscape for Regulation to compare OWASP LLM Top 10 against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.