Under active development Content is continuously updated and improved
Home / Risk Lists / OWASP Top 10 for LLMs

OWASP Top 10 for LLMs v2.0

Security risks for Large Language Model applications

This is a reference tool, not an authoritative source. For official documentation, visit genai.owasp.org.

10 risks

Access Control Risks from excessive permissions and agency granted to models

Configuration Risks from system prompt and configuration exposure

Data Security Risks related to sensitive data exposure and leakage

Infrastructure Risks related to embeddings, vectors, and RAG systems

Model Integrity Risks affecting the integrity of model behavior and outputs

Output Security Risks from improper handling of model-generated content

Prompt Security Risks related to prompt manipulation and injection attacks

Reliability Risks from hallucinations and misinformation

Resource Management Risks from unbounded resource consumption

Supply Chain Risks from third-party components, models, and data sources