OWASP Top 10 for LLM Applications: What to Assess

Updated · Assessed Solutions

LLM agentEmailPaymentsDatabaseFilesPrompt injectionExcessive agencyOWASP TOP 10 FOR LLM APPLICATIONS

Short answer: The OWASP Top 10 for LLM Applications lists the most critical security risks in systems built on large language models, including prompt injection, sensitive information disclosure, and excessive agency. Assessing against it means checking each AI system for the conditions that make those risks exploitable and proving that mitigating controls exist.

Key takeaways

  • Prompt injection becomes critical when a model can call tools.
  • Excessive agency is the condition that turns manipulation into harm.
  • Assess risks against actual capabilities, not in isolation.

Risks that deserve the most attention

  • Prompt injection: untrusted input that changes the model’s behavior, especially dangerous when the model can call tools.
  • Sensitive information disclosure: personal data, secrets, or proprietary information exposed through prompts, retrieval, or logs.
  • Excessive agency: tools and permissions broader than the task requires, so a manipulated model can take harmful actions.
  • Supply chain risk: third-party models, plugins, and datasets introduced without review.

Because the list is updated periodically, organizations should confirm they are assessing against the current edition.

Turning the list into checks

The most useful assessment connects risks to the system’s actual capabilities. Prompt injection is a moderate concern for a read-only assistant and a critical one for an agent that can move money. Checks should therefore consider tool authority, data access, and human oversight together, not in isolation.

How Assessed Govern assesses it

Assessed Govern maps discovered capabilities to AI attack vectors, including prompt injection that can reach tool authority, and ties findings to ARISE controls and the OWASP Top 10 for LLM Applications, MITRE ATLAS, and NIST AI RMF. Findings that raise risk can block deployment through the CI/CD governance gate.

Questions

What is the most common LLM application risk?

Prompt injection is the most widely discussed, and its impact grows with the tools and permissions available to the model.

Is the OWASP LLM Top 10 a compliance standard?

No. It is an industry awareness document, but it is widely used as a reference for AI security assessments and maps to controls in broader frameworks.

How does excessive agency differ from prompt injection?

Prompt injection is how an attacker influences the model. Excessive agency is the condition that lets that influence cause harm, such as broad write permissions or unreviewed financial actions.

Join the beta

Tell us about your organization and which platform you want to run. We use these details only to contact you about the beta, as described in our Privacy Policy.

Interested in

By signing up, you agree that Assessed Solutions may contact you about the beta. You can ask us to delete your details at any time. See our Privacy Policy.

You're on the list.

Thank you for your interest. We will contact you at the email you provided with next steps for the beta.