What category of awareness document this is
The OWASP Top 10 for LLM Applications (also called the OWASP GenAI LLM Top 10) is a community-developed awareness document for developers, architects, data scientists, security practitioners, and organizations building or operating applications that use large language models. It is meant to educate and to start conversations about critical LLM-application risks. It is not the web OWASP Top 10, not ASVS, and not NIST AI RMF.
Who it commonly frames: AI path readers leaving G1 through G3, AppSec readers who already met the sentence that the LLM Top 10 is separate and had no labeled home, buyers who treat OWASP AI verified as one seal, and Reference or AI RMF readers who already see GenAI LLM Top 10 2026 as a separate list. This is an industry awareness list. It is not a U.S. statute, and it is not a certification scheme.
What security people most often confuse: they fold ten LLM checkboxes, web Top 10:2025, an ASVS level, AI RMF 1.0, finished G1 through G3, and an Atlas lesson into one seal. This page keeps those objects apart. The web Top 10 explainer at /learn/explainers/owasp-top-10/ stays the web awareness list. The ASVS explainer at /learn/explainers/owasp-asvs/ stays the verification project. The Reference card at /reference/frameworks/owasp-top-10-2025/ stays the web framework summary. The AI RMF explainer at /learn/explainers/nist-ai-rmf/ is the labeled literacy home. The field guide at /reference/frameworks/nist-ai-rmf-1-0/ stays the edition pin. This explainer complements them. It does not replace any of them, and it does not reprint category bodies.
Edition pin
The edition string to teach is OWASP Top 10 for LLM Applications 2026 (OWASP GenAI LLM Top 10 2026, Version 2026). Official hubs are https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/ and https://github.com/GenAI-Security-Project/GenAI-LLM-Top10 (canonical Markdown under 2026/final/). Re-opened on 2026-09-26: the GitHub README and 2026/README.md both say published August 4, 2026. Zenodo version DOI 10.5281/zenodo.22109015 also says published August 4, 2026 (Version 2026). The genai.owasp.org resource page stamp reads August 3, 2026. This card pins edition 2026 and treats 2026-08-04 as the GitHub canonical release day, with the August 3, 2026 resource stamp noted. The two hubs do not show one identical calendar day (UNKNOWN which stamp to treat as the only day). This card does not invent a third date. If either date shifts, or a newer edition appears, update this pin and treat the older claim as UNKNOWN.
The concept DOI 10.5281/zenodo.22109014 resolves to the newest edition. The version DOI above is the 2026 edition specifically. One line on naming, not an encyclopedia: the 2026 list reorders and renames some themes relative to 2025. Excessive Agency is LLM03:2026. Hidden Context Exposure is a 2026 name. Improper Output Handling is LLM10:2026. This page does not teach the 2025 order, and it does not invent an adoption percentage from a download headline.
LLM01 through LLM10 are category labels
The ten names in the table on this page are the official OWASP Top 10 for LLM Applications 2026 category labels. They are awareness category labels, not a finished test plan, and not permission to paste official attack scenarios into Atlas. This page stops at the name. It does not reprint the risk text, the mitigations, or the weakness lists on the official pages.
The AI path already teaches two of these names without this page becoming a fourth lesson. G1, prompt injection and retrieval trust at /learn/topics/prompt-injection-and-retrieval/, practices the LLM01 theme. G2, excessive agency at /learn/topics/excessive-agency/, practices the LLM03 theme. G3, human oversight at /learn/topics/human-oversight-gates/, practices a human gate. Open those lessons for the practice. This page does not rewrite them. Finishing G1 through G3 does not seal this list.
A hallway poster that checks all ten boxes is still a poster. The label tells people which conversation they are in. It does not close a test, and it does not require anyone to memorize ten category essays. A separate OWASP Top 10 for Agentic Applications exists for cases where a model acts as an actor. This page names that list only. It does not open an Atlas card for it.
Name the theme, then keep the evidence
Pick one real or synthetic LLM-powered feature. LanePay on the AI path, and ScheduleClerk in the agent lab, are the synthetic examples already on this site. Use an LLM Top 10 theme as a shared name for the conversation, then move to verifiable evidence: tool authorization, a human gate, retrieval trust, or a blast-radius limit.
Practice stays on the existing pages. G1 is /learn/topics/prompt-injection-and-retrieval/. G2 is /learn/topics/excessive-agency/. G3 is /learn/topics/human-oversight-gates/. The lab is /labs/agent-tool-auth/. The path is /learn/paths/ai-agent-security/. The landscape segment, when you are comparing control purposes, is /landscape/segments/ai-agent-security/. This page does not replace those.
When the risk is a classic web application risk, use the web Top 10 explainer at /learn/explainers/owasp-top-10/. When the need is leveled verification requirements, use ASVS at /learn/explainers/owasp-asvs/. When the need is Govern, Map, Measure, and Manage placement, use the AI RMF explainer at /learn/explainers/nist-ai-rmf/. The field guide stays at /reference/frameworks/nist-ai-rmf-1-0/. Do not collapse those lanes. The six-map comparison is /reference/frameworks/compare/. It does not add a seventh map object for this list.
What this card is not
Not an LLM course. Not a G4 revival. Not a mitigations encyclopedia. Not a CWE dump. Not exploit or red-team PoC homework. Not a web Top 10 rewrite. Not an ASVS rewrite. Not a replacement for the AI RMF explainer at /learn/explainers/nist-ai-rmf/. Not a replacement for the web Top 10 explainer at /learn/explainers/owasp-top-10/, the ASVS explainer at /learn/explainers/owasp-asvs/, the Reference card at /reference/frameworks/owasp-top-10-2025/, or G1 through G3. Not a rewrite of those lessons. Not permission to invent an adoption statistic. Not a claim that G1 through G3 done means this list is sealed. Not an Atlas attestation of LLM Top 10 completion.
Not a CSF 2.0 profile. Outcomes live on /learn/topics/outcomes-then-controls/ and on /reference/frameworks/nist-csf-2-0/. The OWASP row on the six-map comparison says the purpose is awareness of common application risks, that the web list is not ASVS and not the LLM Top 10, that certifiable is No, and that a typical misuse is treating the list as a complete test standard. A row is not this page. This page is the labeled home for the separate LLM list that row names.
Rewrite the one-line claim
Replace "we are Top 10, ASVS, LLM Top 10, AI RMF, OWASP AI, and Atlas AI compliant" with a reading sentence. We use OWASP GenAI LLM Top 10 2026 as a limited LLM-application awareness list (LLM01 through LLM10 labels). That is different from web Top 10:2025, from ASVS 5.0.0 verification depth, from NIST AI RMF 1.0 (/learn/explainers/nist-ai-rmf/), from finished G1 through G3 practice, and from an Atlas seal.
When a slide says "OWASP AI verified" or "LLM Top 10 compliant," privately ask which edition, which theme was actually tested, and which application evidence supports it, and whether the live need is LLM awareness, web Top 10 awareness, ASVS verification depth, or AI RMF placement. Do not paste proprietary prompts, customer data, or exploit kits into Atlas.
Ten LLM boxes are not secure, not web Top 10, not ASVS, not AI RMF, and not an Atlas seal
Teaching table only. It does not assign a certificate, a finished test, an ASVS level, an AI RMF result, or an Atlas seal.
| Phrase people say | Literacy correction |
|---|---|
| We checked the ten LLM boxes, so the product is secure / certified | OWASP GenAI LLM Top 10 2026 is a limited awareness list. Checking ten themes is not a finished test and not a certification. |
| LLM Top 10 done means web Top 10:2025 done | OWASP Top 10:2025 is a separate web-application awareness list. Explainer: /learn/explainers/owasp-top-10/. Reference card: /reference/frameworks/owasp-top-10-2025/. Do not collapse the lists. |
| LLM Top 10 done means ASVS done / Level N verified | ASVS is a separate requirements and verification project with leveled depth. Level N is not this list. Explainer: /learn/explainers/owasp-asvs/. Awareness labels are not ASVS evidence. |
| LLM Top 10 done means NIST AI RMF 1.0 done | NIST AI RMF 1.0 is a voluntary risk framework (Govern, Map, Measure, Manage). Explainer: /learn/explainers/nist-ai-rmf/. Field guide: /reference/frameworks/nist-ai-rmf-1-0/. Not the same homework. |
| We finished G1 through G3, so LLM Top 10 is sealed / Atlas AI sealed | G1 through G3 teach selected themes (prompt injection, excessive agency, human gates). Path progress is not the full awareness list finished, and Atlas does not issue an AI seal. Lessons: /learn/topics/prompt-injection-and-retrieval/, /learn/topics/excessive-agency/, /learn/topics/human-oversight-gates/. Lab: /labs/agent-tool-auth/. Path: /learn/paths/ai-agent-security/. |
| We are OWASP AI verified / LLM Top 10 compliant / Atlas AppSec sealed | This list is not an Atlas certificate and not a mail-order seal. Completing this lesson is not attested, not certified, and not OWASP AI verified. It is not an Atlas AppSec seal. Six-map comparison: /reference/frameworks/compare/. |
| We can paste the full LLM Top 10 risk text / exploit scenarios / PoCs as Atlas homework | This card does not reprint OWASP risk text, a mitigations encyclopedia, or attack PoCs. Point readers to genai.owasp.org and GitHub 2026/final/. No exploit homework. |
| Ten LLM checkboxes mean attackers will skip us | Awareness themes start a conversation. They do not prove product immunity, and they do not mean attackers will skip you. |
Claims to retire
Ten LLM checkboxes mean a secure product, or an OWASP AI certificate.
OWASP GenAI LLM Top 10 2026 is a limited awareness list. Checking ten themes is not a finished test and not a certification.
Web Top 10, ASVS, the LLM Top 10, and AI RMF are the same homework.
They are different objects. Top 10:2025 names web risk themes. ASVS is leveled verification depth. NIST AI RMF 1.0 places work in Govern, Map, Measure, and Manage. OWASP Top 10 for LLM Applications 2026 is a separate awareness list. Do not collapse them.
Finishing G1 through G3 means the LLM Top 10 is sealed.
G1 through G3 teach selected themes. Path progress is not the full awareness list finished, and Atlas does not issue an AI seal.
This page replaces the web Top 10 explainer, the ASVS explainer, the Reference card, or G1 through G3.
Those pages stay. This page is the labeled home beside them. It does not replace any of them.
Atlas, or a vendor homepage shield, attests LLM Top 10 completion.
Atlas does not issue OWASP LLM Top 10 compliant seals, OWASP AI verified seals, or Atlas AI or AppSec seals. Completing this lesson is not certified. A homepage shield is not evidence a theme was tested on your application.
Full LLM Top 10 risk text and exploit scenarios should be pasted into Atlas lessons.
This card does not reprint the full OWASP risk text, a mitigations encyclopedia, or attack PoCs. Read the official publication instead of pasting it into Atlas.
LLM01:2026 through LLM10:2026, as labels
Official 2026 category names, slogan depth only. This table does not reprint OWASP risk text, mitigations, or CWE identifiers.
| ID | Official name (2026) | Boundary |
|---|---|---|
| LLM01:2026 | Prompt Injection | Awareness category label. Not a finished test. G1 practices this theme. Finishing G1 does not seal this list. |
| LLM02:2026 | Sensitive Information Disclosure | Awareness category label. Not a finished test. |
| LLM03:2026 | Excessive Agency | Awareness category label. Not a finished test. G2 practices this theme. Finishing G2 does not seal this list. |
| LLM04:2026 | Supply Chain | Awareness category label. Not a finished test. |
| LLM05:2026 | Data and Model Poisoning | Awareness category label. Not a finished test. |
| LLM06:2026 | Unbounded Consumption | Awareness category label. Not a finished test. |
| LLM07:2026 | Misinformation | Awareness category label. Not a finished test. |
| LLM08:2026 | Hidden Context Exposure | Awareness category label. Not a finished test. A 2026 name on this list. |
| LLM09:2026 | Vector and Embedding Weaknesses | Awareness category label. Not a finished test. |
| LLM10:2026 | Improper Output Handling | Awareness category label. Not a finished test. A 2026 name on this list. |
CHECK THE CATEGORY
Which sentence matches this page?
Glossary and nearby pages
- OWASP Top 10 explainer (web awareness list, not replaced by this page)
- OWASP ASVS explainer (verification requirements, not replaced by this page)
- OWASP Top 10 Reference card (web framework summary, not replaced by this page)
- NIST AI RMF 1.0 explainer (voluntary framework, not this list)
- NIST AI RMF 1.0 field guide (edition pin companion, not this list)
- Compare the six maps (a row is not this list, and not a seventh map)
- Prompt injection and retrieval trust (G1)
- Excessive agency (G2)
- Human oversight as a designed process (G3)
- Lab: Two tools, one blast radius
- AI application and agent security path
- Landscape: AI application and agent security
- OWASP Top 10 for Agentic Applications 2026 (name only, no Atlas card)
- Outcomes first, then controls (F8a)
- Privacy is not a CIA checkbox
Use the agency page in the sources for the authoritative text. This page has no figure.