The de facto secure-development reference for LLM applications. The 2026 edition keeps prompt injection at number one, raises excessive agency to number three, and weights roughly 7,700 real-world incidents against the community vote; an appendix maps each risk to NIST AI RMF, NIST AI 600-1, MITRE ATLAS, and the CSA AI Controls Matrix.
The de facto secure-development reference for LLM applications. The 2026 edition keeps prompt injection at number one, raises excessive agency to number three, and weights roughly 7,700 real-world incidents against the community vote; an appendix maps each risk to NIST AI RMF, NIST AI 600-1, MITRE ATLAS, and the CSA AI Controls Matrix.
Every entry is checked against its primary source before it is published and shows the date that check was made. How entries are built.
The entry’s permanent URL is its identifier. Add the date you read it — the register is updated as sources change. Register text is licensed CC BY 4.0.