OWASP Top 10 for LLM Applications 2026
LLM threat catalogue (incl. Excessive Agency at #3)
AIGE-OBL-OWASP-LLM. Drawn from chapter 08.
Text alternative
- Clause: OWASP LLM, Top 10 for LLM….
- Duty holder: Not stated.
- Applies from: No date, Voluntary.
- Artefact: Prompt-injection and output-handling controls.
- Layers: Layer 03, Layer 04.
- Evidence record: Evidence record v1.
- Record schema: Evidence record.
- The same topic in 22 other frameworks; the crosswalk section below links each clause.
- Id
AIGE-OBL-OWASP-LLM- Instrument
- OWASP Top 10 for LLM Applications 2026 framework
- Clause
- Top 10 for LLM Applications 2026
- Applies from
- No date Voluntary · Voluntary (2026 edition)
The artefact that evidences it
Prompt-injection and output-handling controls; eval gate.
Patterns that build it
- AI Threat Model (layer 1 and 3)
- Dataset Admission Gate (layer 1 and 2)
- Model Artefact Integrity (layer 2 and 4)
- Rights Requests Against Models (layer 2 and 5)
- Sanctioned AI Gateway (layer 4 and 2)
- Downstream Use Register (layer 2 and 1)
The same topic in other frameworks
From the topic crosswalk: the clauses filed under the same topics as this one. Mappings are illustrative, not a claim of conformity.
Data governance
- EU AI Act Art. 10 Data and data governance (core)
- ISO 42001 A.7 Data for AI systems (core)
- TC260 Framework 3.0 TC260 2.1.3 Data safety risks (core)
- China GenAI Measures GenAI Art. 7 Training-data lawful sourcing (core)
- China GenAI Measures GenAI Art. 8 Data-annotation standards (core)
- China GenAI Measures GenAI Art. 11 Protection of user input and records (core)
- China Deep Synthesis DeepSyn Art. 14 Training-data management (core)
- GB/T 45654 GB/T 45654 Corpus security Training-corpus (data) security requirements (core) (clause not verified)
- EU AI Act Art. 10(2)(f)–(g) Examination for possible biases; measures to detect, prevent and mitigate them (core)
- GDPR Art. 5(1)(c) Data minimisation (core)
- GDPR Art. 25 Data protection by design and by default (core)
- ISO 42001 A.7.3 Acquisition of data (core) (clause not verified)
- CSA AICM DSP-20 Data Provenance and Transparency (core)
- UK ATRS ATRS 2.4.3 Development data specification (core)
- Singapore GenAI GenAI 2 Data (core)
- GAO AI Accountability 2.1 Sources: document sources and origins of data used to develop the models (core)
- GAO AI Accountability 2.2 Reliability: assess reliability of data used to develop the models (core)
- EU AI Act Art. 4a Special-category data for bias detection
- ISO 42001 A.4 Resources for AI systems
- NIST AI RMF MAP 2 MAP 2: Categorization of the AI system is performed
- NIST AI RMF MEASURE 2.10 MEASURE 2.10: Privacy risk of the AI system is examined and documented
- NIST AI RMF MEASURE 2.11 MEASURE 2.11: Fairness and bias are evaluated and results are documented
- TC260 Framework 3.0 TC260 5.1 Model R&D safety guidelines
- EU AI Act Art. 53 Obligations for providers of general-purpose AI models
- EU AI Act Art. 53(1)(c) Copyright policy, including rights reservations
- EU AI Act Art. 5(1)(e) Prohibited: untargeted scraping of facial images
- GPAI Code Copyright 1.1–1.5 Commitment 1: Copyright policy (Measures 1.1 to 1.5)
- GDPR Art. 9 Processing of special categories of personal data
- CSA AICM DSP-21 Data Poisoning Prevention & Detection
- GAO AI Accountability 2.4 Variable selection: assess data variables used in the AI component models
- GAO AI Accountability 2.5 Enhancement: assess the use of synthetic, imputed, and/or augmented data
Runtime guardrails
- ISO 42001 A.9 Use of AI systems (core)
- NIST AI RMF MANAGE 2 MANAGE 2: Strategies to maximize AI benefits and minimize negative impacts are planned, prepared, implemented, documented, and informed by relevant AI actors (core)
- TC260 Framework 3.0 TC260 App. 2 II.5 Dynamic runtime management (core)
- TC260 Framework 3.0 TC260 3.2.1 Technological countermeasures for agentic AI (core)
- China GenAI Measures GenAI Art. 10 Guided, bounded use (core)
- China GenAI Measures GenAI Art. 14 Stop unlawful generation (core)
- China Deep Synthesis DeepSyn Art. 10 Input and output review (core)
- CSA AICM TVM-13 Guardrails (core)
- CSA AICM AIS-09 Input Validation (core)
- CSA AICM AIS-10 Output Validation (core)
- Singapore Agentic Agentic 2.3.1 During design and development, use technical controls (core)
- EU AI Act Art. 5 Prohibited AI practices
- EU AI Act Art. 15 Accuracy, robustness and cybersecurity
- ISO 42001 A.6 AI system life cycle
- China Algo. Rec. AlgoRec Art. 8 Periodic algorithm review
- China Algo. Rec. AlgoRec Art. 9 Feature database for unlawful content
- EU AI Act Art. 5(1)(a)–(b) Manipulative techniques; exploitation of vulnerabilities
- GPAI Code Safety C5 Commitment 5: Safety mitigations
Robustness, security and evaluations
- EU AI Act Art. 15 Accuracy, robustness and cybersecurity (core)
- EU AI Act Art. 55 Obligations for providers of general-purpose AI models with systemic risk (core)
- ISO 42001 A.6 AI system life cycle (core)
- NIST AI RMF MEASURE 2 MEASURE 2: AI systems are evaluated for trustworthy characteristics (core)
- TC260 Framework 3.0 TC260 3 Technological countermeasures (core)
- TC260 Framework 3.0 TC260 App. 2 II.6 Sandbox validation and red teaming (core)
- China Deep Synthesis DeepSyn Art. 15 Technology management and algorithm verification (core)
- China Deep Synthesis DeepSyn Art. 20 Security assessment of new products (core)
- GB/T 45654 GB/T 45654 Security assessment Security-assessment requirements for generative AI services (core) (clause not verified)
- GPAI Code Safety 3.2 Measure 3.2: Model evaluations (core)
- NIST AI RMF MEASURE 2.7 MEASURE 2.7: AI system security and resilience as identified in the MAP function are evaluated and documented (core)
- CSA AICM MDS-06 Adversarial Attack Analysis (core)
- CSA AICM MDS-07 Robustness against Adversarial Attack / Model Hardening (core)
- Singapore GenAI GenAI 5 Testing and Assurance (core)
- Singapore GenAI GenAI 6 Security (core)
- Singapore Agentic Agentic 2.3.2 Before deploying, test agents (core)
- CoE Convention CoE Art. 16(2)(g) Testing before first use and when significantly modified (core)
- OECD AI Principles OECD 1.4 Robustness, security and safety (core)
- G7 Code G7 Action 1 Identify, evaluate and mitigate risks across the lifecycle, including testing (core)
- GAO AI Accountability 3.7 Assessment: assess performance against defined metrics to ensure the AI system functions as intended and is sufficiently robust (core)
- EU AI Act Art. 60 Testing of high-risk AI systems in real-world conditions outside AI regulatory sandboxes
- ISO 42001 9.1 Monitoring, measurement, analysis and evaluation
- TC260 Framework 3.0 TC260 5.3.14 Resilience
- China GenAI Measures GenAI Art. 17 Security assessment
- EU AI Act Art. 15(3) Declared accuracy levels and metrics
- EU AI Act Art. 9 Risk management system
- EU AI Act Art. 42(3) Presumption of conformity for cybersecurity (Cyber Resilience Act)
- GPAI Code Safety C6 Commitment 6: Security mitigations
- GDPR Art. 32 Security of processing
- NIST AI RMF MEASURE 2.1 MEASURE 2.1: Test sets, metrics, and details about the tools used during TEVV are documented
- NIST AI RMF MEASURE 1 MEASURE 1: Appropriate methods and metrics are identified and applied
- CSA AICM AIS-05 Application Security Testing
- OWASP Agentic ASI05 Unexpected Code Execution (RCE)
- Korea AI Act Art. 32(1) Safety duties for AI above the compute threshold
- GAO AI Accountability 3.2 Metrics: define performance metrics that are precise, consistent, and reproducible
Supply chain and third parties
- EU AI Act Art. 25 Responsibilities along the AI value chain (core)
- ISO 42001 A.10 Third-party and customer relationships (core)
- NIST AI RMF GOVERN 6 GOVERN 6: Policies and procedures are in place to address AI risks and benefits arising from third-party software and data and other supply chain issues (core)
- NIST AI RMF MAP 4 MAP 4: Risks and benefits are mapped for all AI system components including third-party software and data (core)
- NIST AI RMF MANAGE 3 MANAGE 3: AI risks and benefits from third-party entities are managed (core)
- TC260 Framework 3.0 TC260 App. 2 II.4 Supply chain and tool management (core)
- EU AI Act Art. 25(4) Written agreement with third-party suppliers (core)
- GDPR Art. 28 Processor (core)
- NIST AI RMF MANAGE 3.1 MANAGE 3.1: AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented (core)
- CSA AICM STA-10 Supply Chain Risk Management (core)
- CSA AICM STA-09 Service Bill of Material (BOM) (core)
- OWASP Agentic ASI04 Agentic Supply Chain Vulnerabilities (core)
- EU AI Act Art. 26 Obligations of deployers of high-risk AI systems
- TC260 Framework 3.0 TC260 4.4.4 Open-source ecosystem
- China GenAI Measures GenAI Art. 7 Lawful data and model sources
- China Deep Synthesis DeepSyn Art. 14 Providers and technical supporters
- EU AI Act Art. 22 Authorised representatives of providers of high-risk AI systems
- EU AI Act Art. 23 Obligations of importers
- EU AI Act Art. 24 Obligations of distributors
- EU AI Act Art. 54 Authorised representatives of providers of general-purpose AI models
- GPAI Code Transparency 1.2 Providing relevant information
- GDPR Arts. 44–46 Transfers to third countries
- NIST AI RMF GOVERN 6.2 GOVERN 6.2: Contingency processes are in place to handle failures or incidents in third-party data or AI systems deemed to be high-risk
- UK ATRS ATRS 2.1.4 Third party involvement
- G7 Code G7 Action 11 Implement data input measures and protect personal data and intellectual property
- GAO AI Accountability 2.6 Dependency: assess interconnectivities and dependencies of data streams that operationalize the AI system
Privacy and data protection
- GDPR Art. 5 Principles relating to processing of personal data (core)
- GDPR Art. 6 Lawfulness of processing (core)
- GDPR Art. 25 Data protection by design and by default (core)
- NIST AI RMF MEASURE 2.10 MEASURE 2.10: Privacy risk of the AI system as identified in the MAP function is examined and documented (core)
- CSA AICM DSP-08 Data Privacy by Design and Default (core)
- CoE Convention CoE Art. 11 Privacy and personal data protection (core)
- China GenAI Measures GenAI Art. 7(3) Consent or another lawful basis for personal information in training data (core)
- China GenAI Measures GenAI Art. 11 Protection of user input and records (core)
- GAO AI Accountability 2.8 Security and privacy: assess data security and privacy for the AI system (core)
- EU AI Act Art. 59 Further processing of personal data in the AI regulatory sandbox
- EU AI Act Art. 4a Special-category data for bias detection
- GDPR Art. 35 Data protection impact assessment
- ISO 42001 A.7 Data for AI systems
- CSA AICM DSP-22 Privacy Enhancing Technologies
- UK DUAA UK GDPR Art. 22B Restrictions on automated decision-making
- Singapore GenAI GenAI 2 Data
- OECD AI Principles OECD 1.2 Rule of law, human rights and democratic values, including fairness and privacy
- G7 Code G7 Action 11 Implement data input measures and protect personal data and intellectual property
Agent identity and autonomy
- CSA AICM IAM-18 Agent Access Restriction (core)
- CSA AICM AIS-11 Agents Security Boundaries (core)
- OWASP Agentic ASI03 Identity and Privilege Abuse (core)
- Singapore Agentic Agentic 2.1.2 Bound risks through design by defining agents limits and permissions (core)
- TC260 Framework 3.0 TC260 App. 2 II.2 Identity and access management (core)
- EU AI Act Art. 14 Human oversight
- NIST AI RMF GOVERN 3.2 GOVERN 3.2: Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight of AI systems
- CSA AICM IAM-12 Unique Identities
- OWASP Agentic ASI02 Tool Misuse and Exploitation
- OWASP Agentic ASI07 Insecure Inter-Agent Communication
- OWASP Agentic ASI10 Rogue Agents
- Singapore Agentic Agentic 2.2.2 Design for meaningful human oversight
- TC260 Framework 3.0 TC260 App. 2 II.3 Strengthen human approval
Content provenance and deepfakes
- EU AI Act Art. 50(2) Machine-readable marking of synthetic content (core)
- EU AI Act Art. 50(4) Disclosure of deep fakes (core)
- Korea AI Act Art. 31 Transparency: prior notice, output labelling, realistic synthetic content (core)
- Singapore GenAI GenAI 7 Content Provenance (core)
- G7 Code G7 Action 7 Deploy content authentication and provenance mechanisms where feasible (core)
- China AI Labelling Label Art. 4 Explicit labels for generated content (core)
- China AI Labelling Label Art. 5 Implicit (metadata) labels (core)
- China Deep Synthesis DeepSyn Art. 17 Conspicuous labels for confusable content (core)
- EU AI Act Art. 3(60) Definition of deep fake
- CSA AICM MDS-09 Model Signing/Ownership Verification
- China GenAI Measures GenAI Art. 12 Labelling of generated content
Open controls that evidence it
Draft controls in the open control profiles that map to this row: each states a requirement and the evidence it must leave behind.
-
AIGE-CTL-EVAL-002Network Egress Control (Evaluation environment profile) -
AIGE-CTL-DATA-009Signed Snapshot Integrity (Data admission and privacy profile) -
AIGE-CTL-ASSURE-010Model Artefacts Signed at Build and Verified Before Load (Assurance and evidence profile) -
AIGE-CTL-ASSURE-011Safe Model Formats and Digest-Pinned Third-Party Models (Assurance and evidence profile)
Source
Chapter 08, section OWASP GenAI Security Project, checked against its sources on the review date above.
Machine-readable
- This obligation:
/api/v1/obligations/aige-obl-owasp-llm.json - The register:
/api/v1/obligations.json· CSV - Schema and stability promise: open data and API
Cite this obligation
García Aibar, J. (2026). OWASP Top 10 for LLM Applications 2026 (AIGE-OBL-OWASP-LLM). In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0). https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/obligations/aige-obl-owasp-llm. CC BY 4.0
BibTeX
@misc{aige2026obligation,
author = {Jorge García Aibar},
title = {{OWASP Top 10 for LLM Applications 2026 (AIGE-OBL-OWASP-LLM)}},
howpublished = {In AI Governance Engineering: The Thesis \& Body of Knowledge},
year = {2026},
version = {0.5.0},
doi = {10.5281/zenodo.22956197},
url = {https://aigovernanceengineer.com/obligations/aige-obl-owasp-llm},
note = {Version 0.5.0}
}