OWASP Top 10 for LLM Applications
A published, community-maintained list of the top security risks for applications built on large language models (2025 edition), used here as the shared reference for the attack families. Prompt injection (LLM01) sits at the top for the second edition running.
Defined in 2 GAGE programs, which carry 3 distinct definitions of it. The wording above is taught in AI Governance: Applied Mastery.
How each discipline defines it
The same term does different work depending on who is using it. These are the definitions as each program teaches them, unedited.
A published, community-maintained list of the top security risks for applications built on large language models (2025 edition), used here as the shared reference for the attack families. Prompt injection (LLM01) sits at the top for the second edition running.
The recognized industry catalog of the most critical security vulnerability classes in systems that use large language models, updated for 2025 by the OWASP Gen AI Security Project; the awareness-level reference behind the Security Awareness Check.
A widely used industry catalog of the top security risks for AI applications, in which prompt injection (LLM01) is ranked number one (OWASP Gen AI Security Project, 2025) (see Topic 8.5).
Where it is taught
The exact lessons this term appears in. The first 7 topics of every program are free with a free account.
- ROI and Security Mastery Checks · Assessment and Continuous Learning, AI Literacy & Professional Conduct
- Prompt Injection and Jailbreak Defense · AI Security Fundamentals, AI Literacy & Professional Conduct
- Red-teaming your own system: attacks a motivated user will find · Evaluation and Trust, AI Governance: Applied Mastery
Terms it appears with
Not an alphabetical neighbourhood: these are the terms taught in the same lessons, ranked by how often they appear together.