OWASP Releases Top 10 for LLM Applications: 2026

The threat landscape for AI is changing fast

Mohamed Bilal ⏳ 2 min read
OWASP Releases Top 10 for LLM Applications: 2026

OWASP: Introduction

OWASP (Open Worldwide Application Security Project) is a global open-source initiative dedicated to application security. OWASP is widely regarded for its Top 10 project that publishes a list of critical threats. The OWASP Top 10 serves as a guide to organizations. OWASP recommends that all organizations ensure they have a robust strategy against these top attack vectors.

OWASP has extended its Top 10 project to include the following categories:

  • Web Application Security
  • API Security
  • Gen AI / LLM
  • Machine Learning
  • Mobile
  • Agentic Applications

Top 10 for Gen AI / LLM: 2026

The OWASP Gen AI Security Project is an open-source initiative that primarily focuses on identifying and mitigating security risks and vulnerabilities linked to Gen AI technologies, which include LLMs, agentic systems, and AI applications.

The OWASP Gen AI Security Project has released the 2026 version of its Top 10 for LLM applications. Prompt Injection and Sensitive Information Disclosure remain at the top of the list, while others have been moved around in priority.

OWASP released the first version for LLM in 2023, updated it in 2025, and now in 2026. There have been frequent updates to this project considering the evolving threat landscape presented by the global growth of LLM applications.

  • LLM01:2026 Prompt Injection
  • LLM02:2026 Sensitive Information Disclosure
  • LLM03:2026 Excessive Agency
  • LLM04:2026 Supply Chain
  • LLM05:2026 Data and Model Poisoning
  • LLM06:2026 Unbounded Consumption
  • LLM07:2026 Misinformation
  • LLM08:2026 Hidden Context Exposure
  • LLM09:2026 Vector and Embedding Weaknesses
  • LLM10:2026 Improper Output Handling

Owasp-LLM

Firewall

Many security vendors are offering a firewall to protect against the OWASP Top 10 for LLM. The unprecedented growth in AI applications has led to many security vendors racing to offer an AI firewall. Some notable names include:

  • HiddenLayer
  • Palo Alto
  • Akamai
  • Cloudflare
  • Cisco

etc…

Please note: Many vendors are yet to provide complete coverage (multimodal, etc.) or have their products in a nascent stage, so please explore their capabilities through a quick Proof of Concept (POC) before finalizing.