Language models broke an assumption security quietly depended on for decades: that instructions and data are different things. A parameterised SQL query keeps user input from becoming code. A model has no such boundary. System prompt, user message and retrieved document all arrive as one stream of tokens with equal standing. That single fact sits underneath most of the list below.
The OWASP Top 10 for LLM Applications (2025) names the risks every team shipping AI features should understand. OWASP has since published a 2026 edition; this guide uses the 2025 identifiers. Here is the short, practical version, with a real example for each.
LLM01:2025 Prompt injection
Crafted input that overrides intended behaviour, directly or indirectly. The indirect variant is the dangerous one: instructions hidden in a document, email or web page the model retrieves. A crafted email made a mainstream copilot exfiltrate inbox data when a user simply asked for a summary, with no click required. There is no patch, because this is a vulnerability class, not a bug.
LLM02:2025 Sensitive information disclosure
The model reveals confidential data from its training set, system prompt or retrieval corpus. A support assistant leaking another customer's records through a crafted query against a poorly isolated vector store is the canonical case.
LLM03:2025 Supply chain
Compromise through malicious model weights, datasets or adapters. Loading a tampered model file can execute code via unsafe deserialisation, and malicious fine-tuning adapters circulate on public hubs.
LLM04:2025 Data and model poisoning
Corrupting training or fine-tuning data to plant a backdoor or degrade integrity. Research on sleeper agents showed planted backdoors can survive standard safety training and stay dormant until a trigger.
LLM05:2025 Improper output handling
Treating model output as trusted input to another system. Output containing a markdown image URL that exfiltrates data, or a SQL fragment dropped into an unparameterised query, turns a helpful answer into an exploit.
LLM06:2025 Excessive agency
Giving the model too much permission, capability or autonomy. An AI agent with unrestricted write access and no human approval gate can delete a production database on one bad instruction. The fix is least privilege and gating consequential actions, not a better prompt.
LLM07:2025 System prompt leakage
Exposure of the system prompt, new in the 2025 edition. Asking a model to repeat its instructions for quality assurance can dump rules and any secrets foolishly embedded there. The lesson: a system prompt is not a security boundary.
LLM08:2025 Vector and embedding weaknesses
Risks specific to retrieval systems. Embeddings can be poisoned to force malicious retrieval, leaked across tenants, or inverted to recover approximate source text. Embeddings are reversible, so they are not a substitute for encryption.
LLM09:2025 Misinformation
Confident, fabricated output with downstream impact. Slopsquatting weaponises it: attackers register the package names that models hallucinate, so a developer who installs a suggested nonexistent dependency is compromised.
LLM10:2025 Unbounded consumption
Resource and cost abuse, renamed from model denial of service. Denial of wallet is the sharp version: flooding a pay-per-token endpoint to inflate the victim's cloud bill.
No single guardrail closes this list. Defence is layered: input checks, output validation, provenance tagging, action gating and least privilege, working together. Guardrails are a layer, not a perimeter.
Where this is heading
Agentic systems raise the stakes further, adding memory poisoning, tool description poisoning and cascading hallucination across multi-agent chains. Regulation is arriving alongside: the EU AI Act's duties for stand-alone high-risk systems apply from 2 December 2027.
Agents that call tools add their own list. The OWASP Top 10 for Agentic Applications names risks such as supply-chain attacks on tools and insecure communication between agents, and Cyron AI Security classifies its findings to both lists.
Sources
- OWASP Top 10 for LLM Applications 2025, OWASP GenAI Security Project
- OWASP GenAI LLM Top 10 2026, OWASP GenAI Security Project
- OWASP Top 10 for Agentic Applications for 2026, OWASP GenAI Security Project
- Regulation (EU) 2024/1689 (AI Act), EUR-Lex
- Regulation (EU) 2026/1744, EUR-Lex
- CVE-2025-32711, National Vulnerability Database
- Sleeper Agents: Training Deceptive LLMs that Persist Through Safety Training, arXiv:2401.05566
- Package hallucinations by code-generating LLMs, arXiv:2406.10279
Updated 1 October 2026: edition, regulation dates, the OWASP Top 10 for Agentic Applications, author and sources added.