✳ Industry · OWASP GenAI LLM Top 10

OWASP LLM Top 10:2026 awareness list (not web Top 10, not ASVS, not AI RMF, not an Atlas seal)

An educational overview of OWASP GenAI LLM Top 10 2026 (OWASP Top 10 for LLM Applications, Version 2026) as a limited awareness list for applications that use large language models. LLM01 through LLM10 are category labels. Checking ten boxes is not a finished test, not a certificate, not web Top 10:2025, not ASVS, not NIST AI RMF 1.0, not finished G1 through G3, and not an Atlas AI or AppSec seal.

Industry · OWASP GenAI LLM Top 10Awareness list explainerLast reviewed

What category of awareness document this is

The OWASP Top 10 for LLM Applications (also called the OWASP GenAI LLM Top 10) is a community-developed awareness document for developers, architects, data scientists, security practitioners, and organizations building or operating applications that use large language models. It is meant to educate and to start conversations about critical LLM-application risks. It is not the web OWASP Top 10, not ASVS, and not NIST AI RMF.

Who it commonly frames: AI path readers leaving G1 through G3, AppSec readers who already met the sentence that the LLM Top 10 is separate and had no labeled home, buyers who treat OWASP AI verified as one seal, and Reference or AI RMF readers who already see GenAI LLM Top 10 2026 as a separate list. This is an industry awareness list. It is not a U.S. statute, and it is not a certification scheme.

What security people most often confuse: they fold ten LLM checkboxes, web Top 10:2025, an ASVS level, AI RMF 1.0, finished G1 through G3, and an Atlas lesson into one seal. This page keeps those objects apart. The web Top 10 explainer at /learn/explainers/owasp-top-10/ stays the web awareness list. The ASVS explainer at /learn/explainers/owasp-asvs/ stays the verification project. The Reference card at /reference/frameworks/owasp-top-10-2025/ stays the web framework summary. The AI RMF explainer at /learn/explainers/nist-ai-rmf/ is the labeled literacy home. The field guide at /reference/frameworks/nist-ai-rmf-1-0/ stays the edition pin. This explainer complements them. It does not replace any of them, and it does not reprint category bodies.

Edition pin

The edition string to teach is OWASP Top 10 for LLM Applications 2026 (OWASP GenAI LLM Top 10 2026, Version 2026). Official hubs are https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/ and https://github.com/GenAI-Security-Project/GenAI-LLM-Top10 (canonical Markdown under 2026/final/). Re-opened on 2026-09-26: the GitHub README and 2026/README.md both say published August 4, 2026. Zenodo version DOI 10.5281/zenodo.22109015 also says published August 4, 2026 (Version 2026). The genai.owasp.org resource page stamp reads August 3, 2026. This card pins edition 2026 and treats 2026-08-04 as the GitHub canonical release day, with the August 3, 2026 resource stamp noted. The two hubs do not show one identical calendar day (UNKNOWN which stamp to treat as the only day). This card does not invent a third date. If either date shifts, or a newer edition appears, update this pin and treat the older claim as UNKNOWN.

The concept DOI 10.5281/zenodo.22109014 resolves to the newest edition. The version DOI above is the 2026 edition specifically. One line on naming, not an encyclopedia: the 2026 list reorders and renames some themes relative to 2025. Excessive Agency is LLM03:2026. Hidden Context Exposure is a 2026 name. Improper Output Handling is LLM10:2026. This page does not teach the 2025 order, and it does not invent an adoption percentage from a download headline.

LLM01 through LLM10 are category labels

The ten names in the table on this page are the official OWASP Top 10 for LLM Applications 2026 category labels. They are awareness category labels, not a finished test plan, and not permission to paste official attack scenarios into Atlas. This page stops at the name. It does not reprint the risk text, the mitigations, or the weakness lists on the official pages.

The AI path already teaches two of these names without this page becoming a fourth lesson. G1, prompt injection and retrieval trust at /learn/topics/prompt-injection-and-retrieval/, practices the LLM01 theme. G2, excessive agency at /learn/topics/excessive-agency/, practices the LLM03 theme. G3, human oversight at /learn/topics/human-oversight-gates/, practices a human gate. Open those lessons for the practice. This page does not rewrite them. Finishing G1 through G3 does not seal this list.

A hallway poster that checks all ten boxes is still a poster. The label tells people which conversation they are in. It does not close a test, and it does not require anyone to memorize ten category essays. A separate OWASP Top 10 for Agentic Applications exists for cases where a model acts as an actor. This page names that list only. It does not open an Atlas card for it.

Name the theme, then keep the evidence

Pick one real or synthetic LLM-powered feature. LanePay on the AI path, and ScheduleClerk in the agent lab, are the synthetic examples already on this site. Use an LLM Top 10 theme as a shared name for the conversation, then move to verifiable evidence: tool authorization, a human gate, retrieval trust, or a blast-radius limit.

Practice stays on the existing pages. G1 is /learn/topics/prompt-injection-and-retrieval/. G2 is /learn/topics/excessive-agency/. G3 is /learn/topics/human-oversight-gates/. The lab is /labs/agent-tool-auth/. The path is /learn/paths/ai-agent-security/. The landscape segment, when you are comparing control purposes, is /landscape/segments/ai-agent-security/. This page does not replace those.

When the risk is a classic web application risk, use the web Top 10 explainer at /learn/explainers/owasp-top-10/. When the need is leveled verification requirements, use ASVS at /learn/explainers/owasp-asvs/. When the need is Govern, Map, Measure, and Manage placement, use the AI RMF explainer at /learn/explainers/nist-ai-rmf/. The field guide stays at /reference/frameworks/nist-ai-rmf-1-0/. Do not collapse those lanes. The six-map comparison is /reference/frameworks/compare/. It does not add a seventh map object for this list.

What this card is not

Not an LLM course. Not a G4 revival. Not a mitigations encyclopedia. Not a CWE dump. Not exploit or red-team PoC homework. Not a web Top 10 rewrite. Not an ASVS rewrite. Not a replacement for the AI RMF explainer at /learn/explainers/nist-ai-rmf/. Not a replacement for the web Top 10 explainer at /learn/explainers/owasp-top-10/, the ASVS explainer at /learn/explainers/owasp-asvs/, the Reference card at /reference/frameworks/owasp-top-10-2025/, or G1 through G3. Not a rewrite of those lessons. Not permission to invent an adoption statistic. Not a claim that G1 through G3 done means this list is sealed. Not an Atlas attestation of LLM Top 10 completion.

Not a CSF 2.0 profile. Outcomes live on /learn/topics/outcomes-then-controls/ and on /reference/frameworks/nist-csf-2-0/. The OWASP row on the six-map comparison says the purpose is awareness of common application risks, that the web list is not ASVS and not the LLM Top 10, that certifiable is No, and that a typical misuse is treating the list as a complete test standard. A row is not this page. This page is the labeled home for the separate LLM list that row names.

Rewrite the one-line claim

Replace "we are Top 10, ASVS, LLM Top 10, AI RMF, OWASP AI, and Atlas AI compliant" with a reading sentence. We use OWASP GenAI LLM Top 10 2026 as a limited LLM-application awareness list (LLM01 through LLM10 labels). That is different from web Top 10:2025, from ASVS 5.0.0 verification depth, from NIST AI RMF 1.0 (/learn/explainers/nist-ai-rmf/), from finished G1 through G3 practice, and from an Atlas seal.

When a slide says "OWASP AI verified" or "LLM Top 10 compliant," privately ask which edition, which theme was actually tested, and which application evidence supports it, and whether the live need is LLM awareness, web Top 10 awareness, ASVS verification depth, or AI RMF placement. Do not paste proprietary prompts, customer data, or exploit kits into Atlas.

Ten LLM boxes are not secure, not web Top 10, not ASVS, not AI RMF, and not an Atlas seal

Teaching table only. It does not assign a certificate, a finished test, an ASVS level, an AI RMF result, or an Atlas seal.

Eight phrases people fold into one OWASP AI badge. Not a seal, and not a category essay.
Phrase people sayLiteracy correction
We checked the ten LLM boxes, so the product is secure / certifiedOWASP GenAI LLM Top 10 2026 is a limited awareness list. Checking ten themes is not a finished test and not a certification.
LLM Top 10 done means web Top 10:2025 doneOWASP Top 10:2025 is a separate web-application awareness list. Explainer: /learn/explainers/owasp-top-10/. Reference card: /reference/frameworks/owasp-top-10-2025/. Do not collapse the lists.
LLM Top 10 done means ASVS done / Level N verifiedASVS is a separate requirements and verification project with leveled depth. Level N is not this list. Explainer: /learn/explainers/owasp-asvs/. Awareness labels are not ASVS evidence.
LLM Top 10 done means NIST AI RMF 1.0 doneNIST AI RMF 1.0 is a voluntary risk framework (Govern, Map, Measure, Manage). Explainer: /learn/explainers/nist-ai-rmf/. Field guide: /reference/frameworks/nist-ai-rmf-1-0/. Not the same homework.
We finished G1 through G3, so LLM Top 10 is sealed / Atlas AI sealedG1 through G3 teach selected themes (prompt injection, excessive agency, human gates). Path progress is not the full awareness list finished, and Atlas does not issue an AI seal. Lessons: /learn/topics/prompt-injection-and-retrieval/, /learn/topics/excessive-agency/, /learn/topics/human-oversight-gates/. Lab: /labs/agent-tool-auth/. Path: /learn/paths/ai-agent-security/.
We are OWASP AI verified / LLM Top 10 compliant / Atlas AppSec sealedThis list is not an Atlas certificate and not a mail-order seal. Completing this lesson is not attested, not certified, and not OWASP AI verified. It is not an Atlas AppSec seal. Six-map comparison: /reference/frameworks/compare/.
We can paste the full LLM Top 10 risk text / exploit scenarios / PoCs as Atlas homeworkThis card does not reprint OWASP risk text, a mitigations encyclopedia, or attack PoCs. Point readers to genai.owasp.org and GitHub 2026/final/. No exploit homework.
Ten LLM checkboxes mean attackers will skip usAwareness themes start a conversation. They do not prove product immunity, and they do not mean attackers will skip you.

Claims to retire

Ten LLM checkboxes mean a secure product, or an OWASP AI certificate.

OWASP GenAI LLM Top 10 2026 is a limited awareness list. Checking ten themes is not a finished test and not a certification.

Web Top 10, ASVS, the LLM Top 10, and AI RMF are the same homework.

They are different objects. Top 10:2025 names web risk themes. ASVS is leveled verification depth. NIST AI RMF 1.0 places work in Govern, Map, Measure, and Manage. OWASP Top 10 for LLM Applications 2026 is a separate awareness list. Do not collapse them.

Finishing G1 through G3 means the LLM Top 10 is sealed.

G1 through G3 teach selected themes. Path progress is not the full awareness list finished, and Atlas does not issue an AI seal.

This page replaces the web Top 10 explainer, the ASVS explainer, the Reference card, or G1 through G3.

Those pages stay. This page is the labeled home beside them. It does not replace any of them.

Atlas, or a vendor homepage shield, attests LLM Top 10 completion.

Atlas does not issue OWASP LLM Top 10 compliant seals, OWASP AI verified seals, or Atlas AI or AppSec seals. Completing this lesson is not certified. A homepage shield is not evidence a theme was tested on your application.

Full LLM Top 10 risk text and exploit scenarios should be pasted into Atlas lessons.

This card does not reprint the full OWASP risk text, a mitigations encyclopedia, or attack PoCs. Read the official publication instead of pasting it into Atlas.

LLM01:2026 through LLM10:2026, as labels

Official 2026 category names, slogan depth only. This table does not reprint OWASP risk text, mitigations, or CWE identifiers.

Ten awareness category labels. Not a finished test, and not a certification.
IDOfficial name (2026)Boundary
LLM01:2026Prompt InjectionAwareness category label. Not a finished test. G1 practices this theme. Finishing G1 does not seal this list.
LLM02:2026Sensitive Information DisclosureAwareness category label. Not a finished test.
LLM03:2026Excessive AgencyAwareness category label. Not a finished test. G2 practices this theme. Finishing G2 does not seal this list.
LLM04:2026Supply ChainAwareness category label. Not a finished test.
LLM05:2026Data and Model PoisoningAwareness category label. Not a finished test.
LLM06:2026Unbounded ConsumptionAwareness category label. Not a finished test.
LLM07:2026MisinformationAwareness category label. Not a finished test.
LLM08:2026Hidden Context ExposureAwareness category label. Not a finished test. A 2026 name on this list.
LLM09:2026Vector and Embedding WeaknessesAwareness category label. Not a finished test.
LLM10:2026Improper Output HandlingAwareness category label. Not a finished test. A 2026 name on this list.

CHECK THE CATEGORY

Which sentence matches this page?

Glossary and nearby pages

Use the agency page in the sources for the authoritative text. This page has no figure.

Find your next idea.

Tip: press / to open search. Escape closes this window.