OWASP Top 10 for LLM Applications, 2026
OWASP GenAI Security Project · 2026 edition
The reference list of risks in LLM applications, and the naming scheme used throughout this site. Prompt injection has held the top position across every edition. The 2026 revision renumbered eight of the ten entries, moved excessive agency up to third, dropped improper output handling to tenth, and renamed system prompt leakage to hidden context exposure to cover everything an application holds and never shows you. Where a number changed, this site prints the old one beside it.
Does not prove: that these are the ten most frequent risks in the wild — it is expert consensus weighted with incident data, not telemetry, and it is a list of risks rather than a set of controls. Also note: the 2026 ordering used here was taken from the published edition summary and cross-checked against two independent write-ups that agree exactly. OWASP’s own per-risk pages under genai.owasp.org/llm-top-10 still carried 2025 numbering when this was checked on 31 August 2026, so deep links to individual risks point at the 2025 slugs.