Primary documents, OWASP working group, related projects, named voices, reference resources for the OWASP LLM Top 10 cluster.
Primary documents
- OWASP Top 10 for LLM Applications v2.0 (2025 edition) โ published November 2024. Current version. Free PDF from owasp.org/www-project-top-10-for-large-language-model-applications/.
- OWASP Top 10 for LLM Applications v1.1 โ October 2023 revision of v1.0 (August 2023). Historical reference.
- OWASP GenAI Red Teaming Guide โ companion document. Methodology for red-teaming LLM-integrated applications.
- OWASP LLM Cybersecurity & Governance Checklist โ implementation-oriented companion checklist.
- OWASP AI Exchange โ broader AI security knowledge base. Includes LLM Top 10 content + adjacent AI security guidance.
Operating body
- OWASP Foundation โ Open Worldwide Application Security Project. Long-standing community-driven application security organization. Foundation owns the IP; contributions are community-sourced.
- OWASP LLM AI Cybersecurity & Governance Initiative โ working group established 2023. Multiple sub-working-groups producing the LLM Top 10, the GenAI Red Teaming Guide, the Cybersecurity Checklist, the AI Exchange.
Related OWASP projects
- OWASP Top 10 (Web) โ the original, dating to 2003. Now 2021 edition. Established the "Top 10" format.
- OWASP API Security Top 10 โ API-specific risks.
- OWASP Mobile Top 10 โ mobile-application risks.
- OWASP ASVS (Application Security Verification Standard) โ comprehensive verification standard.
- OWASP SAMM (Software Assurance Maturity Model).
- OWASP Cheat Sheet Series โ practical guidance per topic.
- OWASP Dependency-Check / Dependency-Track โ supply-chain tooling.
Related external taxonomies / frameworks
- MITRE ATLAS โ Adversarial Threat Landscape for Artificial-Intelligence Systems. Adversary tactics, techniques, procedures specific to AI. Complementary to OWASP LLM Top 10.
- MITRE ATT&CK โ adversary TTP framework for general cyber.
- MITRE D3FEND โ defensive countermeasure framework.
- NIST AI RMF GenAI Profile (NIST AI 600-1) โ Category 9 Information Security overlaps with OWASP LLM Top 10.
- NIST SP 800-218A โ AI development security extension (in development).
- AI Risk Atlas (IBM) โ AI risk taxonomy.
- AVID (AI Vulnerability Database) โ community AI vulnerability tracking.
Adversarial-AI research
Academic and industry research that informs the Top 10:
- Carlini et al. โ adversarial ML, model extraction, membership inference.
- Wallace et al. โ universal adversarial triggers, prompt-injection-adjacent.
- Greshake et al. โ indirect prompt injection.
- Various jailbreak research groups โ Anthropic safety team, OpenAI red team, academic labs.
- Anthropic Constitutional AI papers โ defense-side perspectives.
- OpenAI safety publications โ defense-side perspectives.
Practitioner tooling (open source)
Tools that organize attacks by OWASP LLM Top 10 categories:
- PyRIT (Microsoft) โ Python Risk Identification Toolkit for generative AI.
- Garak (NVIDIA) โ LLM vulnerability scanner.
- Promptfoo โ eval framework with red-teaming features.
- DeepEval โ LLM evaluation framework with safety tests.
- Buttercup โ RAG-specific evaluation framework.
- HiddenLayer ModelScanner โ model file vulnerability scanner.
Named contributors and voices
OWASP LLM working group leads
- Steve Wilson โ co-lead of OWASP LLM AI Cybersecurity & Governance Initiative.
- Various working group co-leads โ published widely on LLM security.
Independent AI security voices
- Simon Willison โ practitioner; coined "prompt injection" term (September 2022). Active commentary on the threat landscape.
- Andrej Karpathy โ practitioner perspective on LLM security and engineering.
- Riley Goodside โ early prompt-injection practitioner; demo-driven public communication.
- Pliny the Liberator โ jailbreak demonstrations; public-research role.
- Various AI safety researchers at Anthropic, OpenAI, Google DeepMind, Microsoft, academic labs.
Critical voices
- Various security researchers arguing OWASP LLM Top 10 is incomplete (multimodal, agent-specific, training-time gaps).
- AI safety researchers distinguishing security (this Top 10) from safety (broader concerns).
Reference resources
- owasp.org/www-project-top-10-for-large-language-model-applications/ โ official OWASP LLM Top 10 project page.
- genai.owasp.org โ broader OWASP GenAI Security Project portal.
- MITRE ATLAS at atlas.mitre.org.
- AI Vulnerability Database at avidml.org.
- HuggingFace AI Cookbook โ defensive patterns content.
Regulatory and procurement context
- EU AI Act โ high-risk and GPAI risk management obligations align with OWASP LLM Top 10 content.
- NIST AI RMF GenAI Profile โ Category 9 maps closely to OWASP LLM Top 10.
- ISO 42001 risk register inputs โ practitioners cite OWASP LLM Top 10 for AI-specific risk identification.
- Vendor due diligence โ model provider security postures increasingly evaluated against OWASP LLM Top 10 categories.