The adoption of applications built on large language models, known as LLMs, is shifting part of the traditional security risk into a new layer: the way models receive information, use tools and generate responses that can later end up being executed by other systems. The new OWASP Top 10 for LLM Applications 2026 brings together the ten risks the organization considers most relevant for this type of architecture, from prompt injection to failures in handling the output generated by AI.
The key points on AI security risks in 30 seconds
- OWASP ranks prompt injection first, while also warning about problems that arise when an LLM has access to data, tools and memory.
- Sensitive information disclosure can occur in responses, logs, embeddings, tool calls and other application components.
- Excessive agency raises the risk when an agent can modify data, send messages, execute code or carry out operations without oversight.
- Supply chain issues, data poisoning and unbounded consumption introduce risks that affect both security and costs.
- The last four risks cover misinformation, exposure of hidden system context, weaknesses in vectors and embeddings, and insecure handling of model output.
The report draws an important contrast with many conventional software applications. In a traditional application, the boundaries between data, instructions and permissions are usually defined by code. In an LLM application, many of those boundaries run through a model that processes text, images, documents, memory and tool outputs within the same context stream.
That means security can’t rely solely on trying to detect a malicious input before it reaches the model. OWASP calls for controls around the entire architecture: permissions, tools, data, storage, vendors, output validation and human oversight.
1. Prompt Injection: The Model Doesn’t Know What’s an Instruction and What’s Data
Prompt injection tops the list. The problem occurs when an input alters the model’s intended behavior. That input can be a user message, but it can also be a document retrieved via RAG, an email, a web page, an image, a tool response or information stored in persistent memory.
Part of the difficulty is that the LLM processes instructions and data alike as tokens within its context. If the application mixes the system prompt, user instructions, external documents and memory without controls outside the model, part of that content can end up influencing its behavior.
OWASP distinguishes between direct and indirect injection. The first comes from the user. The second occurs when the model processes external content containing malicious instructions that the user may never even have seen.
The problem grows when the agent has access to tools. An instruction planted in a document can go from being malicious text to triggering an API call, modifying a file or sending out information.
That’s why the report recommends keeping credentials and state-changing capabilities outside the model, reducing permissions and requiring human approval before privileged or irreversible actions. It also calls for especially strict controls when an agent combines access to sensitive information, untrusted content and external communication.
2. Sensitive Information Disclosure: Data Can Leak Through Many Channels
The second risk is sensitive information disclosure. The problem isn’t limited to a chatbot accidentally revealing a secret in a response.
Arguments sent to tools, fragments retrieved via RAG, logs, telemetry, embeddings and even certain observable properties of the system can all become leak channels.
OWASP identifies several points where exposure can occur: during training, inference, fine-tuning or distillation processes, and observability and monitoring stages.
The report also flags vector stores. A backup containing only embeddings shouldn’t automatically be considered harmless, since certain techniques can allow information from the original documents to be reconstructed.
The recommendation is to classify and control data from the source, reduce the amount of information that reaches external vendors, authorize access before retrieving each fragment, and apply detection and filtering mechanisms.
3. Excessive Agency: When the Agent Can Do Too Much
Third place goes to excessive agency. The term describes systems where the LLM has too many tools, too many permissions or too much autonomy.
An assistant designed to read documents, for example, might also have access to functions that modify or delete them. A tool that only needs to query a database might hold write permissions it doesn’t actually need for its task.
The situation gets worse when the model can send emails, execute commands, make payments or modify systems without external approval.
OWASP proposes limiting tools and their functions, applying least-privilege permissions and enforcing authorization outside the LLM itself. The model can decide what it wants to do, but it shouldn’t be the one deciding on its own whether it’s allowed to do it.
Human approval becomes especially important for irreversible or high-impact actions.
4. Supply Chain: The Risk Also Lives in Models and Dependencies
Supply chain risk takes fourth place. In AI applications, the perimeter doesn’t end at software libraries.
It also includes pretrained models, datasets, adapters, third-party components and model conversion, quantization or merging processes.
A seemingly legitimate model may have been tampered with, a dependency may contain malicious code, and a dataset may include contaminated information. There are also risks tied to the licensing and usage terms of certain models and data.
OWASP recommends keeping an up-to-date inventory, verifying the provenance of components, using signatures and integrity checks, and subjecting third-party models to security assessments and red teaming.
5. Data and Model Poisoning: An AI Can Learn the Wrong Behavior
Data and model poisoning affects the system’s integrity. An attacker can try to inject malicious data during training, fine-tuning, embedding generation, RAG pipelines or continuous-learning processes.
The danger is that the system can keep appearing to work fine while absorbing incorrect behavior.
OWASP recommends tracking the lineage of data and models through mechanisms such as software and machine learning bills of materials, known as SBOMs and ML-BOMs, in addition to verifying data provenance and controlling changes throughout their lifecycle.
In RAG applications, it’s also necessary to establish trust boundaries and filter content before it enters the model’s context.
6. Unbounded Consumption: A Single Query Can Become a Cost Problem
Unbounded consumption introduces an economic dimension that doesn’t always show up in traditional systems. An application that allows inferences that are too large or too frequent can suffer availability problems, unexpected costs, or even attempts to extract the model’s capabilities.
Reasoning models, multimodal inputs and agents that make multiple tool calls can multiply the consumption generated by a single request.
One of the scenarios OWASP describes is the so-called Denial of Wallet attack: an attacker triggers enough operations to spike the bill for an AI service priced on usage.
Defending against it requires rate limits, per-user or per-application budgets, controls on input size, and automatic mechanisms to stop certain flows once they exceed expected limits.
7. Misinformation: A Convincing Answer Can Still Be Wrong
The seventh risk is model-generated misinformation. An incorrect answer doesn’t have to sound absurd. It can be convincing enough for an employee, an application or an agent to treat it as true.
The causes can include hallucinations, outdated information, insufficient context, incorrect data or unverified tool outputs.
The risk increases when the LLM’s output triggers actions. A mistake in a conversation can be just a wrong answer. The same mistake inside an agent can change a system’s state, generate code or drive a business decision.
OWASP recommends separating generation from execution, verifying claims before acting, and validating the arguments, permissions and conditions of tool calls.
8. System Prompt Leakage: Hidden Context Also Carries Sensitive Information
The eighth risk involves the exposure of hidden context. Applications typically feed the model instructions the user shouldn’t see directly: system prompts, internal rules, policies, tool schemas, developer instructions or information pulled from internal systems.
Extracting that context isn’t automatically a vulnerability in itself. It becomes a problem when it contains secrets, internal rules, permissions or information that allows someone to understand and attack the application’s defenses.
OWASP’s recommendation is to avoid placing secrets in that context and to keep authorization and security controls outside the LLM.
9. Vector and Embedding Weaknesses: The Search Layer Is Part of the Attack Surface Too
Vectors and embeddings are essential to many RAG applications, but they also introduce specific risks.
An application can turn documents, images, code or audio into numeric representations and use similarity between vectors to decide what information to retrieve. If access control is applied only after that search, a user could learn information about another customer’s documents through result patterns, scores or response times.
OWASP also identifies risks from embedding inversion, membership inference, retrieval manipulation, semantic cache poisoning and attacks on multimodal systems.
The fix is to apply permissions before or during retrieval, separate data by trust level, verify the provenance of sources and monitor for anomalous behavior.
10. Improper Output Handling: Never Trust the LLM’s Output Directly
The tenth risk is improper output handling. The problem occurs when a model-generated response is passed directly to another system without proper validation, sanitization or encoding.
An LLM could generate a SQL query that later gets executed without parameterization, a command that ends up in a shell, or HTML content that gets inserted into a page without proper escaping.
There are also less obvious risks, such as control sequences sent to terminals, admin panels or logging systems.
OWASP recommends treating the model’s output like any other potentially dangerous input. The application should validate results based on the destination context, apply independent authorization controls, and prevent the LLM from directly executing privileged operations.
OWASP’s ranking leaves a clear takeaway for anyone designing AI systems: the model should never become the application’s security boundary. Permissions, credentials, validation and high-impact decisions must stay under controls that sit outside the model.
As LLMs move from answering questions to reading documents, querying databases, executing code and using tools, security increasingly depends on how the entire system is built around them. OWASP’s ten risks work precisely as a checklist for reviewing that architecture before an AI assistant gets access to information or systems that a conventional application could never touch without specific controls.
Frequently Asked Questions
What is the top security risk for LLM applications according to OWASP?
The OWASP Top 10 for LLM Applications 2026 ranks prompt injection first. The risk can come from instructions a user enters directly, or from external content the model processes.
Why is excessive agency dangerous in AI agents?
Because an agent may have the tools and permissions to modify information, execute commands or communicate with other systems. OWASP recommends limiting those capabilities and keeping authorization outside the model.
Can embeddings also cause security problems?
Yes. Embeddings sit on the trust boundary of many RAG applications and can be subject to inversion attacks, poisoning, inference attacks or access-control problems between users.
Can you trust an LLM’s response directly?
Not when that response is going to be used to execute actions or feed other systems. OWASP recommends validating and sanitizing the model’s output before passing it to downstream components.

