guidance
OWASP Top 10 for Large Language Model Applications
InternationalOWASP Foundationpublished
Summary
A community-developed list of significant security risks affecting applications built with large language models.
Why It Matters
It provides practical threat categories that governance, development, testing, and assurance teams can use when evaluating LLM applications.
Key Topics
prompt injectionsensitive information disclosuresupply chaindata poisoningexcessive agencyinsecure output handling
Related Records
NIST AI 600-1
A companion profile to the NIST AI RMF addressing risks and actions specific to generative artificial intelligence.
MITRE ATLAS
A knowledge base of adversary tactics and techniques targeting machine-learning and AI systems.
NIST AI RMF
A voluntary framework for managing risks associated with artificial intelligence across organizational and system lifecycles.