OWASP GenAI Security Project
OWASP Top 10 for LLM Applications 2025
Community-led ranked list of the most critical security risks for applications built with large language models.
8 mapped controls
- preventive
AI-CTRL-002
Training Data Provenance and Lineage
Establish and maintain documented provenance and lineage for all training, fine-tuning, and evaluation data used by AI systems, including legal basis, licensing, sensitivity classification, and transformations applied.
Data GovernanceISO 42001 NIST AI RMF EU AI Act OWASP LLM Top 10 +5v1.0.0 Reviewed 2026-05-01 - detective
AI-CTRL-003
Adversarial Robustness Testing for LLM Systems
Validate that production-bound LLM and agentic AI systems have been tested against direct prompt injection, indirect prompt injection, jailbreak, refusal evasion, and (where applicable) multi-modal adversarial inputs, with documented findings, remediation, and re-test cycles.
Security & Adversarial RobustnessISO 42001 NIST AI RMF EU AI Act OWASP LLM Top 10 +6v1.0.0 Reviewed 2026-05-01 - preventive
AI-CTRL-007
Output Filtering and Content Moderation
Apply layered output filtering and content moderation to LLM and generative AI systems to prevent disclosure of sensitive data, prohibited content, executable payloads, and policy-violating outputs.
Inference & OutputISO 42001 NIST AI RMF EU AI Act OWASP LLM Top 10 +6v1.0.0 Reviewed 2026-05-01 - detective
AI-CTRL-008
AI System Logging and Monitoring
Ensure that AI systems produce logs sufficient to detect abuse, investigate incidents, demonstrate compliance, and reconstruct decisions, with logs protected from tampering and retained per regulatory requirements.
Logging & MonitoringISO 42001 NIST AI RMF EU AI Act OWASP LLM Top 10 +4v1.0.0 Reviewed 2026-05-01 - corrective
AI-CTRL-009
AI Incident Response Procedures
Maintain a tested AI-specific incident response capability that detects, triages, contains, and recovers from AI incidents (prompt injection, model misbehavior, data exfiltration, decision errors with material impact), with regulator notification per applicable rules.
Incident ManagementISO 42001 NIST AI RMF EU AI Act OWASP LLM Top 10 +3v1.0.0 Reviewed 2026-05-01 - preventive
AI-CTRL-010
Model Versioning and Change Control
Ensure that every model promoted to production is uniquely versioned, traceable to its training data, evaluation results, and approval, and subject to controlled change-management with rollback capability.
Change ManagementISO 42001 NIST AI RMF EU AI Act OWASP LLM Top 10 +4v1.0.0 Reviewed 2026-05-01 - preventive
AI-CTRL-013
Personal Data Minimization in Training and Inference
Ensure that personal data used in training, fine-tuning, evaluation, and inference is minimized to the data strictly necessary for the stated purpose, processed under a defensible lawful basis, and subject to the rights of affected individuals.
PrivacyISO 42001 NIST AI RMF EU AI Act OWASP LLM Top 10 +5v1.0.0 Reviewed 2026-05-01 - preventive
AI-CTRL-019
Agentic AI Tool Authorization Boundaries
Restrict agentic AI systems to least-privilege tool authorizations; enforce approval boundaries for high-impact actions; log and review all tool invocations; and prevent privilege escalation across multi-step or multi-agent workflows.
Inference & OutputISO 42001 NIST AI RMF EU AI Act OWASP LLM Top 10 +5v1.0.0 Reviewed 2026-05-01