iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
The OWASP LLM Top 10 is a list of security risk categories for applications built with large language models. The title refers to OWASP’s 2025 edition, but OWASP’s current LLM list is the 2026 edition, published August 4, 2026. For agent builders, the key lesson is to constrain what an agent can access and do: a model weakness becomes more consequential when the application can invoke tools, reach sensitive data, or continue acting without review.
What is the OWASP LLM Top 10?
It is OWASP’s set of ten risk categories for large language model applications. It gives developers and security teams a shared way to identify and discuss weaknesses across an AI application—not a ranked list of guaranteed vulnerabilities, a prevalence study, or a checklist that makes a system secure by itself.
The 2025 edition is useful when assessing systems against that version of OWASP’s framework. It should not be described as the current list: OWASP published a new edition in 2026 with different labels and ordering. The project says the 2026 rankings draw on thousands of real-world AI security incidents and map risks to NIST, MITRE ATLAS, CWE, and OWASP’s agentic framework. That incident basis does not mean the list provides a quantified prevalence rate for each risk. OWASP LLM Top 10
What are the OWASP LLM risks for 2025?
These are the ten categories in the 2025 archive, in that edition’s order. Preserve the year when citing a code: OWASP changed both names and numbering in 2026.
#1 Best Overall
- A FIDO security key with PUF technology provides a unique, hardware-rooted trust anchor that resists tampering and cyber attacks, offering stronger security than conventional designs.
- FIDO2 Certified Protection – Enjoy phishing-resistant security with FIDO2 certification, ensuring top-tier account safety across Windows, macOS, Linux, iOS iOS, Android and more.
- Easy to use & Portable – Designed with a compact USB-C interface, Clife key fits easily on your keychain for secure access anywhere. Simply plug in and authenticate with ease.
- Universal Compatibility – Works seamlessly with hundreds of FIDO2/U2F compliant services, including popular cloud, email, and social platforms.
- Backup recommended – To ensure continuous access, register a backup Clife security key as a spare in case your primary key is lost.
| 2025 code | Risk | What to examine in an agent system |
|---|---|---|
| LLM01:2025 | Prompt Injection | Whether untrusted instructions in user input or retrieved content can steer the model or its connected tools. |
| LLM02:2025 | Sensitive Information Disclosure | Whether prompts, responses, memory, retrieval, or tool access expose protected information. |
| LLM03:2025 | Supply Chain | Whether dependencies, models, datasets, or other components introduce security or integrity risks. |
| LLM04:2025 | Data and Model Poisoning | Whether corrupted training, fine-tuning, or retrieval data can affect model behavior. |
| LLM05:2025 | Improper Output Handling | Whether application code or downstream systems trust model output without appropriate validation. |
| LLM06:2025 | Excessive Agency | Whether the model has unnecessary capabilities, permissions, or freedom to act. |
| LLM07:2025 | System Prompt Leakage | Whether an attacker can elicit hidden instructions or other information included in the system prompt. |
| LLM08:2025 | Vector and Embedding Weaknesses | Whether weaknesses in embedding or vector-store use affect retrieval, confidentiality, or integrity. |
| LLM09:2025 | Misinformation | Whether inaccurate model output can mislead users or drive unsafe downstream decisions. |
| LLM10:2025 | Unbounded Consumption | Whether repeated or expensive use can drive excessive resource use or cost. |
The category names are OWASP’s; the final column translates them into review questions for an agent architecture. Use OWASP’s 2025 archive when you need the edition’s official descriptions.
What changed in the OWASP LLM Top 10 for 2026?
The 2026 edition is not just a renumbering. It changes the order and updates the category names and coverage. The current categories are:
Rank #2
- Hardware-Rooted Security with PUF Technology – PUFido Drive Clife Key uses Physical Unclonable Function technology to generate a unique, hardware-based identity that cannot be duplicated, delivering stronger resistance against tampering and cyber attacks than conventional security keys.
- FIDO2 Certified Phishing-Resistant Protection – Fully compliant with FIDO2/U2F standards, enabling secure passwordless login and two-factor authentication to help protect accounts from phishing and credential theft.
- Security Key + Flash Drive in One Device – Combines a FIDO security key with a built-in USB flash drive, allowing you to carry files and a hardware authentication key together in a single compact device.
- Easy to Use & Portable – Compact USB-C design fits easily on a keychain or in a pocket. Simply plug in the Drive Clife Key to authenticate or access stored files with no extra software required.
- Universal Compatibility – Works with hundreds of FIDO2/U2F compatible services and supports Windows, macOS, Linux, iOS, Android, and other major platforms.
- LLM01:2026 — Prompt Injection
- LLM02:2026 — Sensitive Information Disclosure
- LLM03:2026 — Excessive Agency
- LLM04:2026 — Supply Chain
- LLM05:2026 — Data and Model Poisoning
- LLM06:2026 — Improper Output Handling
- LLM07:2026 — Misinformation
- LLM08:2026 — Hidden Context Exposure
- LLM09:2026 — Vector and Embedding Weaknesses
- LLM10:2026 — Unbounded Consumption
For example, Excessive Agency is LLM06:2025 but LLM03:2026. System Prompt Leakage appears as a 2025 category; Hidden Context Exposure is a 2026 category. Don’t carry a code from one edition into the other without its year. OWASP says the new edition updates rankings and expands threat coverage. See the current list and release details.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesHow does the OWASP Top 10 apply to AI agents?
The LLM list covers application risks that also matter in agent systems, but agents add a consequential operational layer: a model can call tools, access data, and trigger additional model calls across a workflow. A misleading answer can become a sent email, a changed record, or another system action if the agent has the capability and permission to do it.
Rank #3
- Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
- USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
- FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
- Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
- Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
OWASP’s 2025 Excessive Agency guidance identifies three root causes: excessive functionality, excessive permissions, and excessive autonomy. Its email-assistant example illustrates how they interact: malicious content in an email could influence a summarizer that also has the ability to send mail. Restricting the assistant to read-only access and requiring human approval before sending reduce the potential for harm. OWASP’s Excessive Agency guidance
OWASP also publishes a separate Top 10 for Agentic Applications 2026. It complements the LLM list rather than replacing it, with agent-specific risks including Agent Goal Hijack, Tool Misuse and Exploitation, Identity and Privilege Abuse, Memory and Context Poisoning, Insecure Inter-Agent Communication, Cascading Failures, Human-Agent Trust Exploitation, and Rogue Agents. Use the two lists together: the LLM list helps identify model-application weaknesses, while the agentic list focuses attention on how goals, tools, identity, memory, and orchestration can create or amplify risk.
Rank #4
- Dual USB-A and USB-C Security Key – Features both USB-A and USB-C connectors for seamless compatibility across desktops, laptops, and tablets. Supports plug-and-stay use or keychain carry.
- NFC-Enabled for Mobile Access – Built-in NFC allows fast, wireless authentication with Android and iPhone devices. Ideal for mobile logins and on-the-go security.
- FIDO Certified for Strong Authentication – [CHECK COMPATIBILITY before purchase] Fully compliant with FIDO2 and FIDO U2F standards. Works with major platforms like Google, Microsoft, GitHub, and Dropbox.
- Passwordless Login with PinPlex – Supports secure passkey login via WebAuthn and CTAP2 with added protection from PinPlex, a complex PIN system that enhances physical security.
- Multi-Layer Authentication Support – Includes PIV certificates and supports both TOTP and HOTP for strong 2FA/MFA coverage across enterprise and consumer apps.
How do you limit what an AI agent can do?
Start by reducing the agent’s authority, not by assuming a prompt will keep it within bounds. OWASP’s guidance points to limiting capabilities and permissions, human review for sensitive actions, and monitoring downstream activity. In practice, apply those controls at the tool, identity, and workflow layers:
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
- Give each agent only the tools it needs. Avoid broad tool menus when a narrow set of functions will do. Separate read operations from write, send, delete, or execute operations.
- Scope permissions to the task. Use read-only access when possible, and restrict data and actions to the relevant user, resource, or workflow. Do not rely on the model to enforce access control.
- Require approval for consequential actions. Put a human confirmation step before high-impact, destructive, external, or difficult-to-reverse operations. A review step should make clear what the agent proposes to do and with which data or destination.
- Limit autonomy and repetition. Bound how long an agent can run and how many actions or tool calls it can make without renewed authorization. This reduces the chance that one mistake cascades through a workflow.
- Make activity observable. Record the agent’s goal, relevant decisions, tool calls, and outcomes so operators can investigate unexpected behavior and detect downstream effects. OWASP warns that unnecessary autonomy expands the attack surface and limited visibility can let small problems grow into broader failures.
These controls reduce an agent’s blast radius; they do not eliminate prompt injection, misinformation, or other model-application risks. Test the whole workflow, including what happens when retrieved or user-provided content conflicts with the intended task.
How should teams use the lists during a security review?
Use the edition and the system boundary to make a finding actionable. For each relevant risk, record where it enters, what it could affect, and which layer can enforce a control.
- Pin the edition. Name the year and code, such as LLM06:2025 or LLM03:2026. This prevents findings and remediation plans from silently mixing versions.
- Trace the path. Identify whether the weakness involves input, data, model behavior, output handling, tools, identity, or orchestration.
- State the likely impact. Consider confidentiality, integrity, availability, and cost. A single weakness can affect more than one.
- Assign the control to the right layer. A model prompt cannot replace application authorization; tool permissions cannot validate unsafe output; and operational monitoring cannot prevent every bad action. Combine controls where the workflow crosses layers.
- Review agent-specific failure modes too. Check for goal hijacking, tool misuse, privilege abuse, and failures that propagate between agents or workflow stages, using the agentic list alongside the LLM edition.
OWASP’s 2026 announcement reports that more than 100 industry experts, researchers, and practitioners contributed to its Agentic Applications framework. That describes the framework’s contributors, not evidence that a specific control is effective. OWASP GenAI Security Project announcement
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

