Back to Frameworks

OWASP Top 10 for LLM Applications 2025

International
v2025
8 domains
8 controls

OWASP Top 10 security risks specific to Large Language Model (LLM) applications. Identifies the most critical vulnerabilities in AI/LLM systems including prompt injection, data poisoning, and excessive agency. Published by the OWASP GenAI Security Project.

Unverified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

OWASP content is used under the Creative Commons Attribution-ShareAlike 4.0 International License (CC BY-SA 4.0). Original material © OWASP Foundation. See owasp.org for the authoritative source.

Framework Domains (8)

Agency and Resource Bounds

1 controls
Controls in the Agency and Resource Bounds domain of OWASP Top 10 for LLM Applications 20251 controls
CodeTitle
OWASPLLM-6Excessive Agency and Unbounded Consumption (LLM06 + LLM10)

Data and Model Integrity

1 controls
Controls in the Data and Model Integrity domain of OWASP Top 10 for LLM Applications 20251 controls
CodeTitle
OWASPLLM-5Data and Model Poisoning (LLM04)

Governance and Change Management

1 controls
Controls in the Governance and Change Management domain of OWASP Top 10 for LLM Applications 20251 controls
CodeTitle
OWASPLLM-7LLM Governance, Inventory, Risk and Change Management

Monitoring and Testing

1 controls
Controls in the Monitoring and Testing domain of OWASP Top 10 for LLM Applications 20251 controls
CodeTitle
OWASPLLM-8LLM Monitoring, Testing, Red Teaming, and User Education

Output Quality and Safety

1 controls
Controls in the Output Quality and Safety domain of OWASP Top 10 for LLM Applications 20251 controls
CodeTitle
OWASPLLM-2Improper Output Handling and Misinformation (LLM05 + LLM09)

Prompt Security

1 controls
Controls in the Prompt Security domain of OWASP Top 10 for LLM Applications 20251 controls
CodeTitle
OWASPLLM-1Prompt Injection and System Prompt Leakage (LLM01 + LLM07)

Sensitive Information and Privacy

1 controls
Controls in the Sensitive Information and Privacy domain of OWASP Top 10 for LLM Applications 20251 controls
CodeTitle
OWASPLLM-3Sensitive Information Disclosure and Privacy (LLM02)

Supply Chain and Vector Database Security

1 controls
Controls in the Supply Chain and Vector Database Security domain of OWASP Top 10 for LLM Applications 20251 controls
CodeTitle
OWASPLLM-4Supply Chain and Vector/Embedding Weaknesses (LLM03 + LLM08)

Your Compliance Coverage

If you comply with OWASP Top 10 for LLM Applications 2025, you already cover:

Maps to 146 other frameworks

8 total controls
OWASP Top 10:2025
5 source controls mapped|5 target controls covered
63%
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
5 source controls mapped|5 target controls covered
63%
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
5 source controls mapped|5 target controls covered
63%
ISO 27001:2022
5 source controls mapped|9 target controls covered
63%
63%
63%
NIST Privacy Framework
5 source controls mapped|6 target controls covered
63%
MTCS (Singapore)
4 source controls mapped|1 target controls covered
50%
ISO/IEC 27400:2022
4 source controls mapped|3 target controls covered
50%
Azure Security Benchmark
4 source controls mapped|4 target controls covered
50%
ISO/SAE 21434
4 source controls mapped|3 target controls covered
50%
DAMA-DMBOK2 - Data Management Body of Knowledge (2nd Edition)
4 source controls mapped|1 target controls covered
50%
ISO 13485
4 source controls mapped|3 target controls covered
50%
ASD Strategies to Mitigate Cyber Security Incidents
4 source controls mapped|3 target controls covered
50%
ISO 27799
4 source controls mapped|2 target controls covered
50%
ISO/IEC 27011:2024
4 source controls mapped|2 target controls covered
50%
AWS Well-Architected Security Pillar
4 source controls mapped|3 target controls covered
50%
ISO 27017
4 source controls mapped|3 target controls covered
50%
ISO 27018
4 source controls mapped|3 target controls covered
50%
BSI IT-Grundschutz
4 source controls mapped|3 target controls covered
50%
ISO/IEC 27006:2024
4 source controls mapped|2 target controls covered
50%
ISO 27043
4 source controls mapped|3 target controls covered
50%
MARS-E
4 source controls mapped|4 target controls covered
50%
MDS2 (Medical Device)
4 source controls mapped|2 target controls covered
50%
MITRE ATT&CK
4 source controls mapped|1 target controls covered
50%
OWASP SAMM
4 source controls mapped|1 target controls covered
50%
OWASP MASVS
4 source controls mapped|1 target controls covered
50%
OpenSSF Scorecard
4 source controls mapped|1 target controls covered
50%
Oman National Cybersecurity Framework
4 source controls mapped|2 target controls covered
50%
O-RAN WG11 Security Specification
4 source controls mapped|2 target controls covered
50%
NIST SP 800-92
4 source controls mapped|1 target controls covered
50%
NIST SP 800-88
4 source controls mapped|1 target controls covered
50%
NIST SP 800-66
4 source controls mapped|1 target controls covered
50%
NIST SP 800-63-4
4 source controls mapped|2 target controls covered
50%
NIST SP 800-61
4 source controls mapped|1 target controls covered
50%
NIST SP 800-146
4 source controls mapped|1 target controls covered
50%
NIST SP 800-145
4 source controls mapped|1 target controls covered
50%
NIST SP 800-144
4 source controls mapped|1 target controls covered
50%
NIST SP 800-137
4 source controls mapped|1 target controls covered
50%
NIST SP 800-123
4 source controls mapped|1 target controls covered
50%
NAIC Insurance Data Security Model Law (MDL-668)
4 source controls mapped|2 target controls covered
50%
ISO 22739:2024 - Blockchain and Distributed Ledger Technologies Vocabulary
3 source controls mapped|3 target controls covered
38%
FFIEC Cybersecurity Assessment Tool (CAT)
3 source controls mapped|1 target controls covered
38%
IEC 62351 - Power Systems Communication Security
3 source controls mapped|1 target controls covered
38%
Vermont Artificial Intelligence and Consumer Data Act (AICDA)
3 source controls mapped|2 target controls covered
38%
USMCA Chapter 19 - Digital Trade (United States-Mexico-Canada Agreement)
3 source controls mapped|3 target controls covered
38%
ISO/IEC 27010:2015
2 source controls mapped|2 target controls covered
25%
ISO/IEC 23894:2023
2 source controls mapped|2 target controls covered
25%
US EPA Safe Drinking Water Act (SDWA) - Cybersecurity Requirements
2 source controls mapped|1 target controls covered
25%
Tennessee Information Protection Act (TIPA)
2 source controls mapped|4 target controls covered
25%
TEFCA - Trusted Exchange Framework and Common Agreement
2 source controls mapped|1 target controls covered
25%
SWIFT CSCF
2 source controls mapped|1 target controls covered
25%
Regulation on the European Health Data Space (EHDS)
2 source controls mapped|1 target controls covered
25%
Russia Federal Law on Personal Data (152-FZ)
2 source controls mapped|3 target controls covered
25%
ISO 19011
2 source controls mapped|2 target controls covered
25%
Armenia Law on Protection of Personal Data (2015)
2 source controls mapped|4 target controls covered
25%
Illinois Biometric Information Privacy Act (BIPA)
2 source controls mapped|3 target controls covered
25%
ISO/IEC 29115:2023 - Entity Authentication Assurance Framework
2 source controls mapped|3 target controls covered
25%
ISO/IEC 23837 - Security Requirements for Quantum Key Distribution
2 source controls mapped|2 target controls covered
25%
AML/CTF Act 2006 (Australia)
2 source controls mapped|1 target controls covered
25%
Bank Secrecy Act / Anti-Money Laundering (BSA/AML)
2 source controls mapped|1 target controls covered
25%
FIDO2 / WebAuthn
2 source controls mapped|1 target controls covered
25%
Florida Digital Bill of Rights (FDBR)
2 source controls mapped|3 target controls covered
25%
FTC GLBA Safeguards Rule (16 CFR Part 314)
2 source controls mapped|2 target controls covered
25%
ITU-T X.805 - Security Architecture for End-to-End Communications
2 source controls mapped|2 target controls covered
25%
API 1164
1 source controls mapped|3 target controls covered
13%
UK Defence Standard 05-138 - Cyber Security for Defence Suppliers
1 source controls mapped|1 target controls covered
13%
AS9100D - Aerospace Quality Management System
1 source controls mapped|3 target controls covered
13%
ISO/IEC 27003:2017
1 source controls mapped|3 target controls covered
13%
ISO 28001:2007 Supply Chain Security Management
1 source controls mapped|2 target controls covered
13%
ISO 22317
1 source controls mapped|1 target controls covered
13%
ISO 22318
1 source controls mapped|1 target controls covered
13%
ISO 20400:2017 - Sustainable Procurement
1 source controls mapped|3 target controls covered
13%
ISO 41001:2018 - Facility Management Systems
1 source controls mapped|2 target controls covered
13%
ISO 39001:2012 - Road Traffic Safety Management
1 source controls mapped|2 target controls covered
13%
ISO 50001:2018 - Energy Management Systems
1 source controls mapped|2 target controls covered
13%
ISO 22313:2020 - Guidance on Business Continuity Management Systems
1 source controls mapped|2 target controls covered
13%
AS9100D:2016 - Quality Management Systems for Aviation, Space, and Defence
1 source controls mapped|2 target controls covered
13%
Automotive SPICE (ASPICE) v4.0 - Process Assessment Model
1 source controls mapped|1 target controls covered
13%
Authorised Economic Operator (AEO) Programmes - Global Standards
1 source controls mapped|2 target controls covered
13%
APRA CPS 230 Operational Risk Management
1 source controls mapped|2 target controls covered
13%
ISO 27019
1 source controls mapped|3 target controls covered
13%
IEC 62443
1 source controls mapped|3 target controls covered
13%
21 CFR Part 211 - Current Good Manufacturing Practice
1 source controls mapped|1 target controls covered
13%
Space ISAC (Information Sharing and Analysis Center) - Threat Framework
1 source controls mapped|1 target controls covered
13%
Annex 11 to EU GMP - Computerised Systems
1 source controls mapped|1 target controls covered
13%
NIS2 Directive
1 source controls mapped|3 target controls covered
13%
NERC CIP
1 source controls mapped|1 target controls covered
13%
Modern Slavery Act 2018 (Australia)
1 source controls mapped|2 target controls covered
13%
ICH Q10 - Pharmaceutical Quality System
1 source controls mapped|1 target controls covered
13%
ICAO Annex 17 - Aviation Security (AVSEC)
1 source controls mapped|1 target controls covered
13%
German Supply Chain Due Diligence Act (LkSG)
1 source controls mapped|2 target controls covered
13%
French Sapin II Law (Law No. 2016-1691)
1 source controls mapped|1 target controls covered
13%
ISO 26000:2010
1 source controls mapped|1 target controls covered
13%
BRCGS Global Standard for Food Safety Issue 9
1 source controls mapped|1 target controls covered
13%
ISO 22316
1 source controls mapped|1 target controls covered
13%
FBI CJIS Security Policy
1 source controls mapped|1 target controls covered
13%
Vietnam Law on Cybersecurity (No. 24/2018/QH14)
1 source controls mapped|2 target controls covered
13%
Turkey KVKK
1 source controls mapped|1 target controls covered
13%
Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA)
1 source controls mapped|1 target controls covered
13%
Privacy Act 1988 (Australia)
1 source controls mapped|2 target controls covered
13%
Pakistan Personal Data Protection Bill 2023
1 source controls mapped|1 target controls covered
13%
13%
Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018)
1 source controls mapped|3 target controls covered
13%
GDPR
1 source controls mapped|3 target controls covered
13%
ISO/IEC 29134:2023
1 source controls mapped|3 target controls covered
13%
ISO/IEC 27014:2020
1 source controls mapped|2 target controls covered
13%
ISO/IEC 29100:2024
1 source controls mapped|3 target controls covered
13%
Azerbaijan Law on Personal Data (2010)
1 source controls mapped|3 target controls covered
13%
Bahrain PDPL
1 source controls mapped|3 target controls covered
13%
Australian Privacy Principles (APPs)
1 source controls mapped|3 target controls covered
13%
ISO/IEC 38500:2024 - Governance of IT
1 source controls mapped|1 target controls covered
13%
Barbados Data Protection Act 2019
1 source controls mapped|3 target controls covered
13%
ISO/IEC 27557:2022 - Organisational Privacy Risk Management
1 source controls mapped|2 target controls covered
13%
APPI
1 source controls mapped|3 target controls covered
13%
COSO Internal Control - Integrated Framework (2013)
1 source controls mapped|1 target controls covered
13%
Estonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019)
1 source controls mapped|1 target controls covered
13%
13%
South Korea PIPA
1 source controls mapped|1 target controls covered
13%
Malaysia PDPA 2010
1 source controls mapped|3 target controls covered
13%
Maryland Online Data Privacy Act of 2024
1 source controls mapped|2 target controls covered
13%
Mauritius DPA
1 source controls mapped|2 target controls covered
13%
Mexico LFPDPPP
1 source controls mapped|2 target controls covered
13%
Minnesota Consumer Data Privacy Act
1 source controls mapped|2 target controls covered
13%
Montana Consumer Data Privacy Act
1 source controls mapped|2 target controls covered
13%
Nebraska Data Privacy Act
1 source controls mapped|5 target controls covered
13%
Nevada Gaming Control Board Cybersecurity Requirements
1 source controls mapped|1 target controls covered
13%
New Hampshire Data Privacy Act
1 source controls mapped|3 target controls covered
13%
New Jersey Data Privacy Act
1 source controls mapped|2 target controls covered
13%
Nigeria Data Protection Act 2023 (NDPA)
1 source controls mapped|5 target controls covered
13%
Nigeria Data Protection Regulation (NDPR)
1 source controls mapped|1 target controls covered
13%
Nigeria Open Banking Regulatory Framework (CBN, 2023)
1 source controls mapped|3 target controls covered
13%
NIST AI 600-1: Generative AI Profile
1 source controls mapped|1 target controls covered
13%
NIST SP 800-122
1 source controls mapped|3 target controls covered
13%
Oregon Consumer Privacy Act
1 source controls mapped|3 target controls covered
13%
OECD AI Principles
1 source controls mapped|1 target controls covered
13%
NRF Cybersecurity and Data Privacy Framework (National Retail Federation)
1 source controls mapped|1 target controls covered
13%
Notifiable Data Breaches Scheme (Australia)
1 source controls mapped|1 target controls covered
13%

Frequently Asked Questions

What is OWASP Top 10 for LLM Applications 2025?

OWASP Top 10 for LLM Applications 2025 is a compliance framework from International with 8 domains and 8 controls. OWASP Top 10 security risks specific to Large Language Model (LLM) applications. Identifies the most critical vulnerabilities in AI/LLM systems including prompt injection, data poisoning, and excessive agency. Published by the OWASP GenAI Security Project. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does OWASP Top 10 for LLM Applications 2025 have?

OWASP Top 10 for LLM Applications 2025 has 8 controls organised across 8 domains. The largest domains are Agency and Resource Bounds (1 controls), Data and Model Integrity (1 controls), Governance and Change Management (1 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does OWASP Top 10 for LLM Applications 2025 map to?

OWASP Top 10 for LLM Applications 2025 maps to 146 other compliance frameworks. The top mapping partners are OWASP Top 10:2025 (63% coverage), NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements (63% coverage), CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 (63% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with OWASP Top 10 for LLM Applications 2025 compliance?

Start your OWASP Top 10 for LLM Applications 2025 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about OWASP Top 10 for LLM Applications 2025 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 8 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.

Get Started Free →

Free forever — no credit card required