The OWASP Top 10 for Large Language Model Applications is a community-maintained awareness document listing critical security risks for LLM-powered applications, such as prompt injection, insecure output handling, and training-data poisoning.
AI Compliance Intelligence
OWASP Top 10 for LLM Applications
OWASP · ai-security
All AI Compliance frameworks → · Official source →
Brel does not assert that any vendor holds this certification unless a company profile cites a verified trust-center or official disclosure.
Editorial overview
Scope
- Risk enumeration and mitigation guidance for LLM application builders
- Not a formal certification or legal regulation
- Versioned publications on OWASP project pages
Relevance to AI products
Security reviews for AI products increasingly map controls to OWASP LLM risks alongside traditional AppSec. Useful for threat modeling RAG apps, agents, and tool-calling systems.
Limitations & caveats
- Guidance document — not a compliance certification
- Should be combined with organizational standards (ISO, SOC 2, NIST)
Related frameworks
Related technologies
Related glossary terms
Why it matters
OWASP Top 10 for LLM Applications is tracked so buyers and builders can understand official scope, issuing bodies, and AI-relevant obligations — without confusing marketing claims with verified attestation or legal status.
Last reviewed
Sources
Correction request
If a technology assignment or hub description is inaccurate, submit a correction via the Corrections Policy.
All technologies → · AI Models → · APIs & SDKs → · Integrations → · Compliance → · Browse all companies → · Explore industries → · Compare →