Updated weekly Last verified 2026-09-09
International · Standard

OWASP Top 10 for LLM Applications (2026)

OWASP GenAI Security Project, Top 10 for LLM Applications 2026
Published
Effective 4 Aug 2026
Verified 9 Sep 2026

The de facto secure-development reference for LLM applications. The 2026 edition keeps prompt injection at number one, raises excessive agency to number three, and weights roughly 7,700 real-world incidents against the community vote; an appendix maps each risk to NIST AI RMF, NIST AI 600-1, MITRE ATLAS, and the CSA AI Controls Matrix.

Primary source: OWASP Top 10 for LLM Applications 2026 →

What it does

The de facto secure-development reference for LLM applications. The 2026 edition keeps prompt injection at number one, raises excessive agency to number three, and weights roughly 7,700 real-world incidents against the community vote; an appendix maps each risk to NIST AI RMF, NIST AI 600-1, MITRE ATLAS, and the CSA AI Controls Matrix.

Every entry is checked against its primary source before it is published and shows the date that check was made. How entries are built.

Related in the register

Careful Adoption of Agentic AI Services — Joint Five Eyes Cyber Security Guidance International · advisory ISO/IEC 42001 International · published China interim measures for generative AI services China · in force Canada Artificial Intelligence and Data Act Canada · struck down

Compared in

Voluntary AI risk and security frameworks →

Cite this entry

The entry’s permanent URL is its identifier. Add the date you read it — the register is updated as sources change. Register text is licensed CC BY 4.0.

AI Reg. Index. “OWASP Top 10 for LLM Applications (2026).” Last verified 9 September 2026. https://airegindex.com/sources/owasp-top-10-for-llm-applications-2026/ Retrieved [access date].
← Back to the register