AI Security: Prompt Injection, Data Leakage and Red TeamingFrameworks: OWASP, MITRE ATLAS and NIST · Lesson 3 of 17

OWASP Top 10 for LLM and Agentic Applications

Article · 14 min · 8 min lecture

Video lecture

OWASP Top 10 for LLM and Agentic Applications

14 chapters · about 8 min · full transcript

Coming soon

Chapter 1 of 14

OWASP Top 10 for LLM and Agentic Applications

  • 2025 list
  • 2026 update
  • Agentic Top 10
  • Coverage matrix

The narrated lecture is in production

Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.

Chapters

Why use a shared taxonomy

The OWASP GenAI Security Project's Top 10 for LLM Applications is the most widely referenced list of LLM application risks. Security teams, auditors, vendors and clients use it as a common vocabulary: "Have you tested for LLM01?" is a question you will hear in procurement and pen-test scoping. Knowing it well lets you communicate risk quickly and check coverage systematically.

The 2025 edition

Published in late 2024 as the 2025 edition, it reflected the rise of RAG and agents:

ID (2025)Risk
LLM01:2025Prompt Injection
LLM02:2025Sensitive Information Disclosure
LLM03:2025Supply Chain
LLM04:2025Data and Model Poisoning
LLM05:2025Improper Output Handling
LLM06:2025Excessive Agency
LLM07:2025System Prompt Leakage
LLM08:2025Vector and Embedding Weaknesses
LLM09:2025Misinformation (absorbing the older "overreliance" theme)
LLM10:2025Unbounded Consumption (broadening the older "model denial of service")

The 2026 update (August 2026)

OWASP released the 2026 edition in early August 2026. Based on OWASP's release and independent summaries (verify against the official document before quoting item text in contracts or reports):

  • No categories were added or removed, but most entries moved.
  • The ranking method changed: it now combines the community vote with analysis of a large corpus of real-world LLM security incidents, rather than relying on the vote alone.
  • Prompt Injection stays at LLM01, with scope expanded to cross-modal attacks (instructions hidden in images, audio or video) and persistence via memory or a RAG corpus.
  • Sensitive Information Disclosure stays at LLM02.
  • Excessive Agency rises to LLM03, reflecting the growth of agents with real permissions.
  • System Prompt Leakage is renamed Hidden Context Exposure (LLM08), widening it from the system prompt to everything the app puts in front of the model that the user cannot see: retrieved documents, tool definitions, memory and configuration.
  • Improper Output Handling moves down to LLM10.

The resulting 2026 order, as reported: LLM01 Prompt Injection; LLM02 Sensitive Information Disclosure; LLM03 Excessive Agency; LLM04 Supply Chain; LLM05 Data and Model Poisoning; LLM06 Unbounded Consumption; LLM07 Misinformation; LLM08 Hidden Context Exposure; LLM09 Vector and Embedding Weaknesses; LLM10 Improper Output Handling.

Practical advice: many existing tools, reports and contracts still reference the 2025 IDs. Always write the edition with the ID ("LLM08:2026 Hidden Context Exposure") and keep a mapping table in your security documentation.

The OWASP Top 10 for Agentic Applications (2026)

In December 2025, the same project published a separate Top 10 for Agentic Applications (IDs ASI01–ASI10) for systems that plan, hold memory, use tools and act with delegated authority. Its categories include agent goal hijack, tool misuse and exploitation, agent identity and privilege abuse, agentic supply chain compromise, unexpected code execution, memory and context poisoning, insecure inter-agent communication, cascading agent failures, human-agent trust exploitation, and rogue agents. Use it alongside the LLM list for any agentic system.

Using the lists well

  • As a coverage checklist, not a complete threat model. Your system may have risks outside both lists (for example business-logic abuse of a discount tool).
  • Map each item to concrete tests in your red-team plan and to controls in your architecture.
  • Map to your threat model IDs, so findings reports use shared language.

Worked example: a coverage matrix

A UK fintech preparing for a client security review built a matrix: rows were OWASP 2026 items plus relevant ASI items; columns were "applies?", "controls", "tests", "last tested", "owner". Two gaps emerged immediately: no tests for LLM09:2026 Vector and Embedding Weaknesses (their RAG index was shared across tenants with filtering done after retrieval), and no controls for ASI06 memory poisoning (their agent stored "user preferences" that any conversation could overwrite). Both were fixed before the review.

Hands-on: coverage matrix template

| Item | Applies? | How it manifests here | Controls (code/config) | Red-team tests | Last tested | Owner |
|------|----------|-----------------------|------------------------|----------------|-------------|-------|
| LLM01:2026 Prompt Injection | yes | reviews + emails in context | spotlighting, tool allowlist, egress block | RT-01..RT-09 | 2026-09-10 | @sec |
| LLM03:2026 Excessive Agency | yes | refund tool | cap in code, approval > limit | RT-12 | | |
| LLM08:2026 Hidden Context Exposure | | | | | | |
| ASI06 Memory & Context Poisoning | | | | | | |

Pitfalls

  • Quoting IDs without the edition year, causing confusion as numbering changed in 2026.
  • Treating the list as exhaustive.
  • Checkbox compliance: "we considered LLM01" without tests is not coverage.

How to measure success

A maintained coverage matrix that references both lists with edition years, where every applicable item has controls and passing tests.

Key takeaways

  • The OWASP LLM Top 10 is the shared vocabulary for LLM app risks; the 2026 edition (Aug 2026) re-ranked the same ten categories.
  • 2026 highlights: Prompt Injection stays LLM01 with cross-modal scope; Excessive Agency rises to LLM03; System Prompt Leakage becomes Hidden Context Exposure (LLM08).
  • Always cite IDs with the edition year and keep a 2025↔2026 mapping.
  • Use the Agentic Top 10 (ASI01–ASI10) for agents, and turn both lists into a coverage matrix with controls and tests.

Check your understanding

Quick questions to lock in the lesson. They don’t count towards your certificate.

  1. What happened to 'System Prompt Leakage' in the 2026 OWASP LLM Top 10?
  2. Why should reports write 'LLM03:2026' rather than just 'LLM03'?

Put it into practice

Build a coverage matrix for one system using the 2026 LLM Top 10 plus relevant ASI items, listing controls, tests and owners.

Enrol for free to save your progress

Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.