OWASP Top 10 for LLM Applications 2025
The security profession's shared vocabulary for language model risk. Two entries decide agent authority: LLM01 prompt injection, because an agent reads untrusted text and then acts, and LLM06 excessive agency, which is the failure of giving a system more functionality, permissions or autonomy than its task requires.
The verdict
Verified
The document exists. The ledger fetched it at its publisher and quotes it.
Key facts
What the sources say
- Record ID
- AAL-2026-0015
- Kind
- Guidance
- Jurisdiction
- Global
- Last verified
- Added
- LLM01:2025 is Prompt Injection, where user prompts alter the behaviour or output of the model in unintended ways.
- LLM06:2025 is Excessive Agency, which OWASP introduces with the observation that an LLM based system is often granted a degree of agency.
- Excessive agency is the entry that maps directly onto tool permissions, so it is the one a deployment review should evidence.
- The list is the 2025 edition of the Top 10 for Large Language Model Applications, published by the OWASP Gen AI Security Project.
Dimension by dimension
2 dimensions, each one stated, silent or open
Limits, Human approval. Stated means the document you can open below says it; silent means the ledger read the document and it does not.
- LimitsStated
- Excessive agency names the control: limit the functions, the permissions and the autonomy an agent's tools grant it.OWASP Gen AI Security Project, Top 10 for LLM Applications, primary source, 15 September 2026.
- Human approvalStated
- The mitigation for high impact actions is a human in the loop rather than tighter prompting.OWASP Gen AI Security Project, Top 10 for LLM Applications, primary source, 15 September 2026.
Figures
Every number, with who measured it and when
- 10 risks
Risks named in the list
OWASP Gen AI Security Project, Top 10 for LLM Applications, primary source, as of .
What it changes
For a team deploying an agent
These two entries are the ones your risk register needs. Prompt injection means an agent that reads a web page has read an instruction from a stranger, so authority must be enforced outside the model. Excessive agency means the tool list is the blast radius: cut it to the task and the injection matters less.
Sources
What this record was verified against
- OWASP Gen AI Security Project, Top 10 for LLM ApplicationsPrimary · 15 September 2026
Related
Records that sit beside this one
OWASP Top 10 for Agentic Applications 2026
Global · verified 15 September 2026
OWASP describes the list as providing practical, actionable guidance to help organisations secure AI agents that plan, act, and make decisions across complex workflows.
Model Context Protocol security best practices
Global · verified 15 September 2026
Token passthrough is an anti pattern where a server accepts a token from a client without validating it was issued to that server, and the document forbids it.
Does a spending limit belong to the agent or to the principal
Global · verified 15 September 2026
The Visa Trusted Agent Protocol addresses recognising an approved agent and its intent, and does not itself carry a spending ceiling.
How does a sub agent's authority attenuate
Global · verified 15 September 2026
RFC 8693 lets a token record that one party is acting for another, but does not require the exchanged token to be narrower.
Can an agent hold a credential of its own
Global · verified 15 September 2026
NIST SP 800-63-4 states that for that publication, person refers only to natural persons.
Who is liable when a delegated agent exceeds its mandate
Global · verified 15 September 2026
The EU AI Act allocates duties to providers and deployers, and does not address an agent acting beyond its instructions.
Cite this record
Free to reuse under CC BY 4.0, with attribution. The record ID AAL-2026-0015 is permanent and is never reused.
- In a sentence
- According to the GAGE Agent Authority Ledger (as of 15 September 2026), owasp top 10 for llm applications 2025.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). OWASP Top 10 for LLM Applications 2025. Agent Authority Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0015-owasp-top-10-for-llm-applications-2025
- MLA
- "OWASP Top 10 for LLM Applications 2025." Agent Authority Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0015-owasp-top-10-for-llm-applications-2025.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "OWASP Top 10 for LLM Applications 2025." Agent Authority Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0015-owasp-top-10-for-llm-applications-2025.
- Permalink
- https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0015-owasp-top-10-for-llm-applications-2025
Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any NIST, IETF or MCP publication.
Back to the full ledger, or every record for Global and every guidance record.
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.