OWASP Top 10 for LLM Applications 2025
Monitoring and Testing

OWASP Top 10 for LLM Applications 2025 OWASPLLM-8: LLM Monitoring, Testing, Red Teaming, and User Education

Operate LLM monitoring + testing + red teaming + user education. Requirements include (a) maintain comprehensive logging for LLM systems including inputs + outputs + tool calls + retrieved content + with appropriate retention + privacy controls + (b) implement monitoring + alerting + anomaly detection for misuse + abuse + injection + poisoning + drift + (c) integrate LLM logs with SIEM + AI-specific observability tools + (d) operate adversarial testing + red teaming + bug bounty for LLM systems including injection + jailbreak + poisoning + extraction + (e) deliver user education + acceptable use + awareness training including LLM limitations + responsible use + reporting + (f) maintain incident response capability for LLM-specific incidents.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.