Skip to main content
VerifiedGuidance

OWASP Top 10 for LLM Applications 2025

The security profession's shared vocabulary for language model risk. Two entries decide agent authority: LLM01 prompt injection, because an agent reads untrusted text and then acts, and LLM06 excessive agency, which is the failure of giving a system more functionality, permissions or autonomy than its task requires.

The verdict

Verified

The document exists. The ledger fetched it at its publisher and quotes it.

Key facts

What the sources say

Record ID
AAL-2026-0015
Kind
Guidance
Jurisdiction
Global
Last verified
Added
  • LLM01:2025 is Prompt Injection, where user prompts alter the behaviour or output of the model in unintended ways.
  • LLM06:2025 is Excessive Agency, which OWASP introduces with the observation that an LLM based system is often granted a degree of agency.
  • Excessive agency is the entry that maps directly onto tool permissions, so it is the one a deployment review should evidence.
  • The list is the 2025 edition of the Top 10 for Large Language Model Applications, published by the OWASP Gen AI Security Project.

Dimension by dimension

2 dimensions, each one stated, silent or open

Limits, Human approval. Stated means the document you can open below says it; silent means the ledger read the document and it does not.

LimitsStated
Excessive agency names the control: limit the functions, the permissions and the autonomy an agent's tools grant it.OWASP Gen AI Security Project, Top 10 for LLM Applications, primary source, 15 September 2026.
Human approvalStated
The mitigation for high impact actions is a human in the loop rather than tighter prompting.OWASP Gen AI Security Project, Top 10 for LLM Applications, primary source, 15 September 2026.

Figures

Every number, with who measured it and when

  1. 10 risks

    Risks named in the list

    OWASP Gen AI Security Project, Top 10 for LLM Applications, primary source, as of .

What it changes

For a team deploying an agent

These two entries are the ones your risk register needs. Prompt injection means an agent that reads a web page has read an instruction from a stranger, so authority must be enforced outside the model. Excessive agency means the tool list is the blast radius: cut it to the task and the injection matters less.

Sources

What this record was verified against

  1. OWASP Gen AI Security Project, Top 10 for LLM ApplicationsPrimary · 15 September 2026

Related

Cite this record

Free to reuse under CC BY 4.0, with attribution. The record ID AAL-2026-0015 is permanent and is never reused.

In a sentence
According to the GAGE Agent Authority Ledger (as of 15 September 2026), owasp top 10 for llm applications 2025.
APA
GAGE (Global Academy of Generative-AI Education). (2026). OWASP Top 10 for LLM Applications 2025. Agent Authority Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0015-owasp-top-10-for-llm-applications-2025
MLA
"OWASP Top 10 for LLM Applications 2025." Agent Authority Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0015-owasp-top-10-for-llm-applications-2025.
Chicago
GAGE (Global Academy of Generative-AI Education). "OWASP Top 10 for LLM Applications 2025." Agent Authority Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0015-owasp-top-10-for-llm-applications-2025.
Permalink
https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0015-owasp-top-10-for-llm-applications-2025

Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any NIST, IETF or MCP publication.

Back to the full ledger, or every record for Global and every guidance record.

GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.