The OWASP Top 10 for Large Language Model Applications is the most widely used checklist for AI application security. It focuses on risks that are new or different when your product includes a language model. Here is each risk in plain terms, with what to do about it.

1. Prompt injection

Attackers craft input, directly or hidden in content the model reads, that overrides your instructions. Mitigate: limit tool permissions, separate untrusted content from privileged actions and require confirmation for side effects.

2. Sensitive information disclosure

The model reveals personal data, secrets or confidential business information from its context or training data. Mitigate: do not put data in the context that the current user may not see; filter outputs for secrets and personal data.

3. Supply chain

Compromised models, datasets, plugins or packages introduce vulnerabilities. Mitigate: use trusted sources, verify model and package integrity and review third-party tools and plugins.

4. Data and model poisoning

Manipulated training, fine-tuning or retrieval data changes the model's behaviour. Mitigate: control and review data sources, track data provenance and evaluate behaviour after every update.

5. Improper output handling

Model output is passed into other systems without validation, leading to XSS, SQL injection or command execution. Mitigate: treat model output like user input. Escape it, validate it and never execute it directly.

typescript
// Wrong: rendering model output as raw HTML
element.innerHTML = modelResponse;
// Better: render as text, or sanitise with a strict allowlist
element.textContent = modelResponse;

6. Excessive agency

An agent has more tools, permissions or autonomy than the task needs, so a mistake or injection causes real damage. Mitigate: least privilege for every tool, scoped credentials and human approval for high-impact actions.

7. System prompt leakage

Secrets or security logic placed in the system prompt are extracted by users. Mitigate: assume the system prompt is public. Never put credentials or authorisation rules in it; enforce rules in code.

8. Vector and embedding weaknesses

Retrieval systems leak documents across users or accept poisoned documents. Mitigate: apply access control at retrieval time and validate what gets indexed.

9. Misinformation

The model produces confident but false answers that users rely on. Mitigate: ground answers in sources, show citations, communicate uncertainty and keep humans reviewing critical outputs.

10. Unbounded consumption

Attackers or bugs drive huge token usage, causing denial of service or large bills. Mitigate: rate limits, input size limits, step budgets for agents and spending alerts.

Key takeaways

  • Treat model input and output as untrusted.
  • Least privilege and human approval contain most agent risks.
  • Never rely on the system prompt for security.
  • Budget and rate-limit usage to prevent runaway costs.