Security & AI

OWASP Top 10 for LLM applications: how to turn the list into a test plan

The OWASP list is a risk-awareness framework, not a certificate or a complete penetration test. Teams should map relevant risks to the actual data, tools and decisions in their application.

Source links included
Editorial image accompanying OWASP Top 10 for LLM applications: how to turn the list into a test plan

Context

What happened, and why it matters

The 2025 list covers prompt injection, sensitive information disclosure, supply-chain risks, data and model poisoning, improper output handling, excessive agency, system prompt leakage, vector and embedding weaknesses, misinformation and unbounded consumption.

Not every item has equal relevance to every chatbot. A public FAQ assistant with no customer data and no tools has a different impact profile from an agent that reads a CRM and sends emails.

Testing should include the surrounding application: authentication, conventional web security, retrieval permissions, output rendering, costs, logging and the human escalation process.

Separate the announcement from the outcome

The named source explains what its publisher announced or recommended. It does not guarantee availability, suitability or results for every organisation.

Details

A useful way to read the update

Test areaEvidence to collect
Threat modelData, users, attackers, tools and consequences
Access controlResults for authorised and unauthorised accounts
Adversarial promptsInputs, outputs and observed tool behaviour
Cost limitsRate, token and provider budget enforcement
RecoveryDisable, revoke, investigate and restore procedure

Work through the guide

Make the next decision clearer.

The OWASP list is a risk-awareness framework, not a certificate or a complete penetration test. Teams should map relevant risks to the actual data, tools and decisions in their application.

Start by separating a published update from what needs changing in your own setup.

Decision check

Put the update in your own context

Decision path

Move from news to a controlled change.

  1. 1ReadPrimary source
  2. 2CheckYour context
  3. 3TestLimited scope
  4. 4ReviewUseful evidence
  5. 5RecordDecision & owner

Practical response

What to do next

  1. 01

    Choose applicable risks through threat modelling.

  2. 02

    Create repeatable tests with expected outcomes.

  3. 03

    Test indirect as well as direct instructions.

  4. 04

    Verify access in source systems, not only prompts.

  5. 05

    Retest after model, prompt or connector changes.

Work through the guide

Start with the question

Choose applicable risks through threat modelling.

Questions

How to use this update responsibly

What period does this article cover?

2025 edition. The article was published on 17 September 2026; check the linked source for changes made later.

Does the announcement mean every organisation should adopt it?

No. Availability, cost, risk and usefulness depend on the specific workflow. A limited test with an owner and measurable acceptance criteria is more informative than a provider demonstration.

How should unverified discussion be treated?

Forum posts, rumours and individual reviews can reveal questions worth testing, but they do not establish prevalence or fact. Confirm material decisions through primary documentation, direct testing and qualified advice where necessary.

Relevant service

Need help applying this to your own setup?

Our security, privacy & accessibility service can help you review the current position, decide what is proportionate and plan a clearly scoped next step.

Explore Security, privacy & accessibility

Sources

Read the original material

These sources support the factual description above. External pages can change after our publication date.

Cookie settings

Choose what this site may use

Optional categories are off by default. Change these choices at any time from the cookie button.

See the cookie policy for the current list and more information about each category.

Accessibility

Adjust your reading experience

These controls supplement the underlying website.

Text size

UserWay is an optional third-party accessibility tool. Loading it connects to UserWay; the built-in controls remain available without it.

Live chat

Start a conversation.

Privacy information

Google reCAPTCHA helps protect this form from spam. Google privacy · Google terms.

Open contact form

Prefer email? [email protected]