OWASP LLM Top 10 anchors

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

Primary documents, OWASP working group, related projects, named voices, reference resources for the OWASP LLM Top 10 cluster.

Primary documents

  • OWASP Top 10 for LLM Applications v2.0 (2025 edition) โ€” published November 2024. Current version. Free PDF from owasp.org/www-project-top-10-for-large-language-model-applications/.
  • OWASP Top 10 for LLM Applications v1.1 โ€” October 2023 revision of v1.0 (August 2023). Historical reference.
  • OWASP GenAI Red Teaming Guide โ€” companion document. Methodology for red-teaming LLM-integrated applications.
  • OWASP LLM Cybersecurity & Governance Checklist โ€” implementation-oriented companion checklist.
  • OWASP AI Exchange โ€” broader AI security knowledge base. Includes LLM Top 10 content + adjacent AI security guidance.

Operating body

  • OWASP Foundation โ€” Open Worldwide Application Security Project. Long-standing community-driven application security organization. Foundation owns the IP; contributions are community-sourced.
  • OWASP LLM AI Cybersecurity & Governance Initiative โ€” working group established 2023. Multiple sub-working-groups producing the LLM Top 10, the GenAI Red Teaming Guide, the Cybersecurity Checklist, the AI Exchange.
  • OWASP Top 10 (Web) โ€” the original, dating to 2003. Now 2021 edition. Established the "Top 10" format.
  • OWASP API Security Top 10 โ€” API-specific risks.
  • OWASP Mobile Top 10 โ€” mobile-application risks.
  • OWASP ASVS (Application Security Verification Standard) โ€” comprehensive verification standard.
  • OWASP SAMM (Software Assurance Maturity Model).
  • OWASP Cheat Sheet Series โ€” practical guidance per topic.
  • OWASP Dependency-Check / Dependency-Track โ€” supply-chain tooling.
  • MITRE ATLAS โ€” Adversarial Threat Landscape for Artificial-Intelligence Systems. Adversary tactics, techniques, procedures specific to AI. Complementary to OWASP LLM Top 10.
  • MITRE ATT&CK โ€” adversary TTP framework for general cyber.
  • MITRE D3FEND โ€” defensive countermeasure framework.
  • NIST AI RMF GenAI Profile (NIST AI 600-1) โ€” Category 9 Information Security overlaps with OWASP LLM Top 10.
  • NIST SP 800-218A โ€” AI development security extension (in development).
  • AI Risk Atlas (IBM) โ€” AI risk taxonomy.
  • AVID (AI Vulnerability Database) โ€” community AI vulnerability tracking.

Adversarial-AI research

Academic and industry research that informs the Top 10:

  • Carlini et al. โ€” adversarial ML, model extraction, membership inference.
  • Wallace et al. โ€” universal adversarial triggers, prompt-injection-adjacent.
  • Greshake et al. โ€” indirect prompt injection.
  • Various jailbreak research groups โ€” Anthropic safety team, OpenAI red team, academic labs.
  • Anthropic Constitutional AI papers โ€” defense-side perspectives.
  • OpenAI safety publications โ€” defense-side perspectives.

Practitioner tooling (open source)

Tools that organize attacks by OWASP LLM Top 10 categories:

  • PyRIT (Microsoft) โ€” Python Risk Identification Toolkit for generative AI.
  • Garak (NVIDIA) โ€” LLM vulnerability scanner.
  • Promptfoo โ€” eval framework with red-teaming features.
  • DeepEval โ€” LLM evaluation framework with safety tests.
  • Buttercup โ€” RAG-specific evaluation framework.
  • HiddenLayer ModelScanner โ€” model file vulnerability scanner.

Named contributors and voices

OWASP LLM working group leads

  • Steve Wilson โ€” co-lead of OWASP LLM AI Cybersecurity & Governance Initiative.
  • Various working group co-leads โ€” published widely on LLM security.

Independent AI security voices

  • Simon Willison โ€” practitioner; coined "prompt injection" term (September 2022). Active commentary on the threat landscape.
  • Andrej Karpathy โ€” practitioner perspective on LLM security and engineering.
  • Riley Goodside โ€” early prompt-injection practitioner; demo-driven public communication.
  • Pliny the Liberator โ€” jailbreak demonstrations; public-research role.
  • Various AI safety researchers at Anthropic, OpenAI, Google DeepMind, Microsoft, academic labs.

Critical voices

  • Various security researchers arguing OWASP LLM Top 10 is incomplete (multimodal, agent-specific, training-time gaps).
  • AI safety researchers distinguishing security (this Top 10) from safety (broader concerns).

Reference resources

  • owasp.org/www-project-top-10-for-large-language-model-applications/ โ€” official OWASP LLM Top 10 project page.
  • genai.owasp.org โ€” broader OWASP GenAI Security Project portal.
  • MITRE ATLAS at atlas.mitre.org.
  • AI Vulnerability Database at avidml.org.
  • HuggingFace AI Cookbook โ€” defensive patterns content.

Regulatory and procurement context

  • EU AI Act โ€” high-risk and GPAI risk management obligations align with OWASP LLM Top 10 content.
  • NIST AI RMF GenAI Profile โ€” Category 9 maps closely to OWASP LLM Top 10.
  • ISO 42001 risk register inputs โ€” practitioners cite OWASP LLM Top 10 for AI-specific risk identification.
  • Vendor due diligence โ€” model provider security postures increasingly evaluated against OWASP LLM Top 10 categories.

See also