NEW!
LLM and Gen AI Data Security Best Practices Guide
Gen AI and LLMs require strong data security to prevent breaches and meet regulations. This paper covers best practices in protection, privacy, and threat mitigation.
NEW!
UK AI Cyber Security Code cites several project resources, guidance.
Learn how OWASP Top 10 for LLM and Generative AI Security guidance and resources provide a supporting foundation for the new UK AI Security Code of Practice and implementation guide.
ANNOUNCEMENT!
OWASP Gen AI Red Teaming Guide Now Available!
This New guide provides key insights and practical framework into GenAI Red Teaming for cybersecurity professionals, AI/ML engineers, researchers & practitioners.
Join us @ RSAC 2025 This Year
OWASP LLM & Gen AI Security Summit 2025, April 30th
Join us for the 2nd annual OWASP LLM & Gen AI Security Summit on Wednesday, April 30th, 8:30 AM - 1:00 PM. Explore key topics like the 2025 Top 10, Securing Agentic Apps, Gen AI Data, Applied AI Red Teaming, AI Governance, and more.
Share your email - and we'll keep you updated.
UPDATED LIST FOR Q1, 2025, NEW CHEAT SHEETS
Explore The 2025 AI Security Solutions Landscape
The AI Security Landscape maps risks from the LLM Top 10, LLMSecOps, and solutions for securing GenAI apps throughout the LLMSecOps lifecycle.
GET INVOLVED
Research Initiative: Agentic Application Security
The Agentic Security Research Initiative examines the security impacts of agentic systems using advanced frameworks (e.g., LangGraph, AutoGPT) and features like Llama 3's agentic capabilities.
ANNOUNCEMENT!
OWASP Unveils 2025 LLM Top 10 Risks, Sponsorship Program & Inaugural Sponsors
The updated 2025 LLM Top 10 highlights risks like Unbounded Consumption, Vector/Embedding RAG guidance, System Prompt Leakage, and more.
ANNOUNCEMENT!
LLM Top 10 Project Expands Focus and Publishes New AI Security Guidance
Announcement introduces new initiatives for AI Threat Intelligence, Secure AI Adoption, AI Security Landscape, DeepFake response guidance, and an AI Security Center of Excellence.
NEW!
Deepfake Threat Preparation and Response Guidance
The OWASP LLM Top 10 team announces the release of a comprehensive guide for mitigating and responding to deepfake risks.
NEW!
AI Security Center of Excellence Guide
Establishing a Generative AI Security COE is essential. This document offers a best practices framework for teams, including cross-functional OKRs and KPIs, to streamline implementation.
Join the Newsletter
Introduction
Businesses, eager to harness the potential of LLMs and Generative AI are rapidly integrating them into their operations and client facing offerings. Yet, the breakneck speed at which LLMs are being adopted and the rapid evolution of Gen AI application architectures (e.g. RAG, agentic apps) have outpaced the establishment of comprehensive security and risk management protocols, leaving many applications and their organizations vulnerable to high-risk issues.
Who is it for?
Our primary audiences include technology and business leaders, developers, data scientists, and security experts tasked with developing, building and managing the security risks of applications leveraging LLM and Generative AI technologies.
![](https://i0.wp.com/genai.owasp.org/wp-content/uploads/2024/12/Guidence-and-Inititive-Summary11.30.24-1-e1733168852836.png?fit=1024%2C517&ssl=1)
Affiliated Standards Organizations and Projects
![NIST_logo.svg](https://i0.wp.com/genai.owasp.org/wp-content/uploads/2024/04/NIST_logo.svg.png?fit=300%2C79&ssl=1)
![ENISA_logo](https://i0.wp.com/genai.owasp.org/wp-content/uploads/2024/04/ENISA_logo.png?fit=300%2C205&ssl=1)
![ncsc](https://i0.wp.com/genai.owasp.org/wp-content/uploads/2024/04/ncsc.png?fit=300%2C188&ssl=1)
![CEN-CENELEC.thumb.png.efabe09d2e7fbd7c64b2cef7ea5a7182](https://i0.wp.com/genai.owasp.org/wp-content/uploads/2024/04/CEN-CENELEC.thumb_.png.efabe09d2e7fbd7c64b2cef7ea5a7182.png?fit=200%2C133&ssl=1)
![5bfdce88cd3820f7c5c21e02_mitre](https://i0.wp.com/genai.owasp.org/wp-content/uploads/2024/04/5bfdce88cd3820f7c5c21e02_mitre.png?fit=300%2C180&ssl=1)
![1712241004772](https://i0.wp.com/genai.owasp.org/wp-content/uploads/2024/04/1712241004772.jpeg?fit=300%2C143&ssl=1)
![large_blob](https://i0.wp.com/genai.owasp.org/wp-content/uploads/2024/04/large_blob.png?fit=196%2C196&ssl=1)
![openssf-open-source-security-foundation-logo-648066AA6E-seeklogo.com](https://i0.wp.com/genai.owasp.org/wp-content/uploads/2024/04/openssf-open-source-security-foundation-logo-648066AA6E-seeklogo.com_.png?fit=300%2C115&ssl=1)
![iso-1-logo-png-transparent](https://i0.wp.com/genai.owasp.org/wp-content/uploads/2024/04/iso-1-logo-png-transparent.png?fit=300%2C300&ssl=1)
![Linux_Foundation_logo](https://i0.wp.com/genai.owasp.org/wp-content/uploads/2024/04/Linux_Foundation_logo.png?fit=300%2C91&ssl=1)
![](https://i0.wp.com/genai.owasp.org/wp-content/uploads/2024/12/OWASP-T10-for-LLM-and-GenAI-2025-Draft.png?fit=1024%2C576&ssl=1)
Explore the Top 10 for 2025
Creating the OWASP Top 10 for LLM Applications list is a significant undertaking, built on the collective expertise of an international team of more than 500 experts and over 150 active contributors. Our contributors come from diverse backgrounds, including AI companies, security companies, ISVs, cloud hyperscalers, hardware providers, and academia.
View the Top 10 for LLMs 2023-24.
What The Industry Is Saying
“‘The OWASP Guide to Preparing and Responding to Deepfake Events’ very clearly outlines the current threats and guidance on how to deal with some specific events. This guide acts as. . . .
- - Henry Patishman, Executive Vice President for Identity Verification Solutions,
- Regula
“Generative AI is transforming industries at an unprecedented rate, but with that innovation comes new security challenges. The OWASP Top 10 for LLM project helps ensure that businesses are not. . . .
- - Rich Campagna, SVP, Product Management, NextGen Firewall,
- Palo Alto Networks
¨The OWASP Top 10 for LLMs has become an indispensable resource for organizations addressing the challenges of Generative AI threats. As the project continues to evolve, it provides vital guidance. . . .
- - Itamar Golan, CEO & Co-founder of Prompt Security,
“We’re proud to sponsor and contribute to the OWASP LLM Top 10 project, a pioneering collaboration to establish essential security standards for confident Generative AI adoption, providing actionable insights to. . . .
- - Lasso Security,
“Snyk is proud to sponsor these latest OWASP findings that ultimately help to advance a shared mission to secure AI-generated code. Together, we’re ensuring the world’s developers have expert-accurate, effortless. . . .
- Snyk
“HiddenLayer is proud to partner with OWASP, a leader in advancing security for AI. Their focus on tackling the biggest risks to LLMs supports our mission to secure AI and. . . .
- - Chris Sestito, CEO and Co-Founder,
- HiddenLayer
“PromptArmor is proud to contribute our novel threat intelligence on AI risks to the OWASP Top 10 for LLMs project, and is excited to sponsor the project’s mission to create. . . .
- PromptArmor
“The 2025 OWASP Top 10 for LLMs effectively debunks the misconception that securing GenAI is solely about protecting the model or analyzing prompts. The research offers valuable insights into how. . . .
- - Rehan Jalil, CEO,
- Securiti AI
The unique value of this project lies in its systematic organization of threats and clear definition of necessary solutions across the LLM Ops lifecycle, particularly significant in today’s emerging GenAI. . . .
- NRI Secure
“OWASP’s AI Security Solutions Landscape is a landmark guide for security professionals. It outlines key risks and critical controls for securing LLMs and Generative AI applications, while highlighting the innovative. . . .
- - Gilad Elyashar, Chief Product Officer,
- Aqua Security
Frequently Asked Questions
The OWASP Top 10 for LLMs is a list of the most critical vulnerabilities found in applications utilizing LLMs. It was created to provide developers, data scientists, and security experts with practical, actionable, and concise security guidance to navigate the complex and evolving terrain of LLM security
The primary audience is developers, data scientists, and security experts tasked with designing and building applications and plug-ins leveraging LLM technologies.
While the list shares DNA with vulnerability types found in other OWASP Top 10 lists, it does not simply reiterate these vulnerabilities. Instead, it delves into the unique implications these vulnerabilities have when encountered in applications utilizing LLMs. The goal is to bridge the divide between general application security principles and the specific challenges posed by LLMs
The creation of the OWASP Top 10 for LLMs list was a major undertaking, built on the collective expertise of an international team of nearly 500 experts, with over 125 active contributors. The team brainstormed and proposed potential vulnerabilities, refined these proposals down to a concise list of the ten most critical vulnerabilities, and each vulnerability was then further scrutinized and refined by dedicated sub-teams and subjected to public review.
Yes, the first version of the list will not be the last. The team expects to update it on a periodic basis to keep pace with the state of the industry. They will be working with the broader community to push the state of the art, and creating more educational materials for a range of uses.
In the News
OWASP Top 10 Risks for Large Language Models: 2025 updates
- Barracuda Networks
- 2024-11-20
- Blog
OWASP Warns of Growing Data Exposure Risk from AI in New Top 10 List for LLMs
- Infosecurity Magazine
- 2024-11-20
- James Coker
OWASP Top 10 for LLM and new tooling guidance targets GenAl security
- Reversing Labs
- 2024-11-14
- John P. Mello Jr
OWASP Releases AI Security Resources
- Security Boulevard
- 2024-11-08
- Juan Perez
Events
- In-Person
- Feb
- 11
- Feb
- 13
Developerweek 2025
- In-Person
- Apr
- 28
- May
- 1
RSA Conference 2025
- In-Person
- Sep
- 21
- Sep
- 22
InfoSec World 2024
- In-Person
- Sep
- 10
- Sep
- 12
Cloud Security Alliance – SECtember.AI
Project Sponsors
![](https://i0.wp.com/genai.owasp.org/wp-content/uploads/2024/12/HL_logoH_2C-6751f859a4b00-300x70-1.webp?fit=300%2C70&ssl=1)
![](https://i0.wp.com/genai.owasp.org/wp-content/uploads/2024/12/panw_RGB_Logo_Positive-6751dc166e898-300x83-1.webp?fit=299%2C83&ssl=1)
![](https://i0.wp.com/genai.owasp.org/wp-content/uploads/2024/11/Snyk-Brand-Vertical-Logo-Dark-6744978e5f731.png?fit=300%2C225&ssl=1)
![](https://i0.wp.com/genai.owasp.org/wp-content/uploads/2024/11/Mend-io-logo-512x512px%402x-6744515e34285.png?fit=300%2C300&ssl=1)
![](https://i0.wp.com/genai.owasp.org/wp-content/uploads/2024/11/Pangea_logo_512-672994166099b-300x100-1.webp?fit=299%2C100&ssl=1)
![](https://i0.wp.com/genai.owasp.org/wp-content/uploads/2024/11/Black-and-Color-6728e22053ffe-300x60-1.webp?fit=300%2C60&ssl=1)
![](https://i0.wp.com/genai.owasp.org/wp-content/uploads/2024/10/synack-logo-horizontal-blue-black-300px-671815a612179-1.png?fit=300%2C72&ssl=1)
![](https://i0.wp.com/genai.owasp.org/wp-content/uploads/2024/09/Lasso-Logo-66d96c494de33.jpg?fit=300%2C186&ssl=1)
![](https://i0.wp.com/genai.owasp.org/wp-content/uploads/2024/07/dark-text-66a4376e13e7c.png?fit=300%2C285&ssl=1)