OWASP LLM Top 10: AI Security Risks and Fixes

The OWASP Top 10 for LLM Applications 2025 explained: prompt injection, excessive agency, RAG risks, and the cloud controls that actually stop them.
The OWASP Top 10 for LLM Applications 2025 is the industry reference list of the ten most critical security risks in generative AI systems: prompt injection, sensitive information disclosure, supply chain, data and model poisoning, improper output handling, excessive agency, system prompt leakage, vector and embedding weaknesses, misinformation, and unbounded consumption. If you are moving into cloud and AI platform security, this list is the fastest way to learn what actually breaks in production AI systems, and what employers now expect you to be able to defend.
AI security is no longer a research topic. Organizations are running chatbots, retrieval systems, copilots, and autonomous agents inside the same cloud accounts that hold their customer data. The security controls those systems need are mostly cloud security controls applied to a new attack surface, which is exactly why cloud engineers are well positioned to move into AI security roles.
Why AI security is now a cloud security job
Almost every production LLM application is a cloud application. It runs on managed compute, calls a hosted model endpoint, pulls context from a vector database, holds credentials in a secrets manager, and reaches other services through an identity. When something goes wrong, the blast radius is defined by cloud IAM, network boundaries, logging, and key management, not by the model itself.
That means the disciplines you already build in cloud security transfer directly:
- Least privilege and scoped roles limit what a compromised agent can do.
- Network segmentation limits which systems a model can reach.
- Secrets management keeps API keys out of prompts and code.
- Centralized logging gives you the evidence to investigate an incident.
- Encryption and key control protect the data feeding retrieval pipelines.
The new part is understanding how attackers manipulate the model layer. That is what the OWASP list gives you.
The OWASP Top 10 for LLM Applications 2025 at a glance
The 2025 edition, published by the OWASP GenAI Security Project, reordered earlier risks and added categories that reflect real deployments rather than lab experiments. OWASP released a 2026 edition in August 2026 with updated rankings, broader threat coverage, and mappings to NIST, MITRE ATLAS, CWE, and the Top 10 for Agentic Applications, so check the project site for the current ranking before citing it in an audit. The underlying risk categories below remain the working vocabulary of the field.
| ID | Risk | What typically goes wrong | Core mitigation |
|---|---|---|---|
| LLM01 | Prompt Injection | Untrusted input changes model behavior or instructions | Treat all model input as untrusted, constrain privileges, add human approval for sensitive actions |
| LLM02 | Sensitive Information Disclosure | Secrets, PII, or internal data appear in responses | Data minimization, input and output filtering, strict access control on retrieval sources |
| LLM03 | Supply Chain | Compromised models, datasets, plugins, or dependencies | Verify model and package provenance, maintain an AI bill of materials, scan dependencies |
| LLM04 | Data and Model Poisoning | Tainted training, fine tuning, or embedding data skews behavior | Vet data sources, validate pipelines, monitor for anomalous outputs |
| LLM05 | Improper Output Handling | Model output is passed unchecked into code, SQL, shells, or browsers | Validate and encode output before any downstream execution or rendering |
| LLM06 | Excessive Agency | The model can take more actions than the use case requires | Minimize tools, scope permissions per action, require approval for high impact steps |
| LLM07 | System Prompt Leakage | Instructions or embedded secrets are extracted from the system prompt | Never place secrets or authorization logic in prompts, enforce controls outside the model |
| LLM08 | Vector and Embedding Weaknesses | RAG stores leak data or return content the user should not see | Apply tenant and role filters at retrieval time, secure and monitor the vector store |
| LLM09 | Misinformation | Confident but wrong output is trusted by users or systems | Ground responses in verified sources, cite them, keep humans in the loop for critical decisions |
| LLM10 | Unbounded Consumption | Unlimited queries drive runaway cost or denial of service | Rate limits, quotas, budget alerts, timeouts on long running requests |
The risks that matter most in day to day work
Prompt injection is an authorization problem
Prompt injection happens when instructions in user input, a web page, a PDF, or a retrieved document change what the model does. Indirect injection is the harder case: a model summarizing a document can be told, inside that document, to exfiltrate data or call a tool.
You cannot filter your way to safety here. The durable fix is architectural. Assume the model can be persuaded to attempt anything it has permission to attempt, then make sure it does not have permission to do damage. That is the same reasoning behind least privilege in cloud IAM, which we cover in detail in our guide to AWS IAM security best practices.
Improper output handling is classic appsec
If model output is inserted into a SQL query, a shell command, an HTML page, or generated code that gets executed, you have injection risk of the traditional kind. Treat model output like user input from an untrusted browser: validate, encode, and never execute it blindly.
Excessive agency is where agents get expensive
An agent with broad API access, write permissions, and no approval step is a single successful injection away from a real incident. Reduce the tool list to what the workflow needs, scope each credential to a specific action, and require human confirmation for anything that spends money, deletes data, or changes access.
Vector and embedding weaknesses break multi tenant apps
Retrieval augmented generation is now standard. The common failure is missing authorization at retrieval time: everything is embedded into one index, and the filter that separates one customer from another is either weak or absent. The vector store needs the same access control discipline as the database behind it.
Unbounded consumption is a cost and availability risk
Token based pricing makes denial of wallet a real threat. Rate limits per user, hard quotas, request timeouts, and cloud budget alarms belong in the design, not in the postmortem.
Agentic AI raises the stakes
In December 2025 the OWASP GenAI Security Project released the Top 10 for Agentic Applications, addressing systems that plan, persist state, use tools, and delegate to other agents. Highlighted threat areas include agent behavior hijacking, tool misuse and exploitation, and identity and privilege abuse.
The pattern is consistent: as autonomy increases, identity and permission design becomes the dominant control. An agent is effectively a non human user in your cloud environment. It needs an identity, a scoped role, credential rotation, and an audit trail, just like any service account.
How to build AI security skills employers can verify
Reading the list is the easy part. Employers hire people who can show the work. A practical progression looks like this:
- Build a small LLM application in a cloud account you control. A retrieval chatbot over your own documents is enough.
- Attack it. Attempt direct and indirect prompt injection, try to extract the system prompt, and try to retrieve documents your test user should not see.
- Fix it. Add retrieval filters, restrict the tool list, move secrets out of prompts, and add output validation.
- Instrument it. Log prompts, tool calls, and retrieval decisions to your cloud logging service so an investigator could reconstruct a session.
- Add guardrails on cost. Rate limits, quotas, and budget alerts.
- Document it. A short threat model mapped to the OWASP risks, with the control you implemented for each, is a portfolio artifact hiring managers can actually evaluate.
That build, break, fix, document loop is the core of how the PrimeSec Academy curriculum is structured across AWS, Azure, Google Cloud, and AI security, and it is what the hands on projects are designed to produce.
Where AI security fits in a cloud security career
You do not need to choose between cloud security and AI security. In practice, AI security roles are asking for cloud fundamentals plus a working understanding of model specific risks. Identity, logging, encryption, and network controls remain the foundation. The OWASP list is the layer you add on top.
If you are still deciding whether this direction fits your background, the eligibility quiz takes a few minutes and gives you a realistic read on where to start. If you are further along and want to see how AI security connects to recognized credentials, our certifications path shows how cloud and security certifications stack alongside practical AI security work.
Frequently asked questions
What is the OWASP Top 10 for LLM Applications?
It is a community developed list published by the OWASP GenAI Security Project that identifies the ten most critical security risks in applications built on large language models. The 2025 edition covers prompt injection, sensitive information disclosure, supply chain, data and model poisoning, improper output handling, excessive agency, system prompt leakage, vector and embedding weaknesses, misinformation, and unbounded consumption. OWASP published an updated 2026 edition in August 2026, so confirm the current ranking on the project site before citing it formally.
Is prompt injection the same as jailbreaking?
They overlap but are not identical. Jailbreaking generally means getting a model to bypass its own safety rules. Prompt injection means untrusted content changes the behavior of an application built around the model, including content the model retrieves rather than content the user types. Indirect prompt injection is often the more serious risk in enterprise systems.
Do I need to be a machine learning engineer to work in AI security?
No. Most AI security work is applied security engineering: identity and access management, secrets handling, input and output validation, logging, monitoring, and threat modeling. A strong cloud security foundation matters more than the ability to train models, though understanding how models behave is important.
How is agentic AI security different from LLM security?
Agentic systems can plan, keep state, call tools, and delegate to other agents, which means a single compromise can cascade across systems rather than producing one bad answer. OWASP published a separate Top 10 for Agentic Applications to address risks such as agent behavior hijacking, tool misuse, and identity and privilege abuse.
Can traditional security tools detect prompt injection?
Partially. Web application firewalls and content filters catch some patterns, but they cannot reliably distinguish legitimate instructions from malicious ones in natural language. The stronger controls are architectural: limit what the model is permitted to do, validate output before it is used, and require human approval for high impact actions.
How long does it take to learn AI security fundamentals?
If you already have cloud and security basics, you can build a working understanding of the OWASP LLM risks and implement meaningful controls in a few weeks of consistent hands on practice. Building a portfolio that demonstrates that ability to employers usually takes longer and benefits from structured projects and feedback.
Build the skills, then prove them
AI systems are being deployed faster than most organizations can secure them, and the people who can close that gap are cloud security engineers who understand the model layer. If you want a structured path from fundamentals to defended capstone across AWS, Azure, Google Cloud, and AI security, review the full curriculum or enroll in the program and start building.
