AI Compliance Intelligence

OWASP Top 10 for LLM Applications

OWASP · ai-security

IssuerOWASP
Categoryai-security
Reviewed

All AI Compliance frameworks → · Official source →

Brel does not assert that any vendor holds this certification unless a company profile cites a verified trust-center or official disclosure.

Editorial overview

The OWASP Top 10 for Large Language Model Applications is a community-maintained awareness document listing critical security risks for LLM-powered applications, such as prompt injection, insecure output handling, and training-data poisoning.

Scope

  • Risk enumeration and mitigation guidance for LLM application builders
  • Not a formal certification or legal regulation
  • Versioned publications on OWASP project pages

Relevance to AI products

Security reviews for AI products increasingly map controls to OWASP LLM risks alongside traditional AppSec. Useful for threat modeling RAG apps, agents, and tool-calling systems.

Limitations & caveats

  • Guidance document — not a compliance certification
  • Should be combined with organizational standards (ISO, SOC 2, NIST)

Related frameworks

Related technologies

Related glossary terms

Why it matters

OWASP Top 10 for LLM Applications is tracked so buyers and builders can understand official scope, issuing bodies, and AI-relevant obligations — without confusing marketing claims with verified attestation or legal status.

Last reviewed

Sources

Correction request

If a technology assignment or hub description is inaccurate, submit a correction via the Corrections Policy.

All technologies → · AI Models → · APIs & SDKs → · Integrations → · Compliance → · Browse all companies → · Explore industries → · Compare →