AI Vulnerabilities - OWASP LLM Top 10 2026
The 2026 OWASP Top 10 for LLM Applications is the first built on real incident data. Here is what moved, what it means, and how to test your own AI against it.
10/8/20263 min read


OWASP LLM Top 10 for 2026: What Changed and Why
If you build, buy, or govern anything powered by a large language model, there is one list worth knowing by heart: the OWASP Top 10 for LLM Applications. In August 2026, OWASP's GenAI Security Project published the new edition, and for the first time it is backed by more than expert opinion.
Here is what changed, and what to do about it.
The big shift: this edition is built on real incidents
Every previous version of the list was built on the judgment of hundreds of practitioners. That vote is still the backbone. But this year the project did something new: it tested that judgment against the record of what has actually gone wrong.
The team assembled 7,714 real-world AI security incidents from public vulnerability databases and an AI-harm database, then classified the 6,639 that carried enough detail to sort. The final ranking weighs the practitioner vote at roughly three quarters, and the incident evidence at the remaining quarter.
The result is the most evidence-grounded version of the list to date, and the gaps between what practitioners fear and what the data shows are some of the most useful parts of the whole document.
The 2026 list
LLM01 Prompt Injection
LLM02 Sensitive Information Disclosure
LLM03 Excessive Agency
LLM04 Supply Chain
LLM05 Data and Model Poisoning
LLM06 Unbounded Consumption
LLM07 Misinformation
LLM08 Hidden Context Exposure
LLM09 Vector and Embedding Weaknesses
LLM10 Improper Output Handling
What moved, and what it tells you
No category was dropped and none was newly invented, but eight of the ten changed position. That reordering is the signal.
Prompt Injection held the number one spot, and Sensitive Information Disclosure held number two. Interestingly, prompt injection stays on top by practitioner vote even though it is comparatively rare in the clean incident record, a sign that teams are defending it hard.
Excessive Agency jumped from sixth to third. As more organizations give AI the ability to take actions, call tools, and make decisions, the risk of it doing too much has climbed fast.
Unbounded Consumption rose from tenth to sixth, and Misinformation rose from ninth to seventh.
Improper Output Handling fell from fifth to tenth.
System Prompt Leakage was renamed and broadened into Hidden Context Exposure. This is the most important edit. It is no longer just about protecting the system prompt. It now covers everything your application places in front of the model without the user seeing it: retrieved documents in a RAG pipeline, conversational memory, tool schemas, and internal application state. If any of that leaks and reveals secrets or policy logic, it is in scope.
The 2026 edition also maps every risk to the frameworks that matter for governance and assurance, including the NIST AI Risk Management Framework, MITRE ATLAS, CWE, and the CSA AI Controls Matrix.
From list to action
A ranked list is awareness. The harder question is whether your own AI systems are exposed to any of these risks, and most teams simply do not know.
Two moves close that gap:
Test your systems against these risks directly. You cannot manage what you have not measured. Our platform, MATUR.ai, includes an AI vulnerability assessment that lets you point it at your own LLM endpoint and probe it for several of the exact risks on this list, including prompt injection, sensitive data exposure, and leakage of hidden context. It is a fast way to see where you stand before someone else finds out.
Govern the findings, do not just collect them. A test tells you where the holes are. Governance makes sure they get closed and stay closed. That is where mapping these risks to ISO/IEC 42001 and the NIST AI RMF, and getting an independent look, turns a scan into real assurance.
Why this matters now
The threats on this list are not theoretical. The 2026 edition passed 10,000 downloads within 48 hours of release, because the people building and securing AI are treating it as the baseline. Regulators, customers, and boards increasingly expect you to know these risks and show you have addressed them.
Knowing the list is step one. Proving your AI stands up to it is the real work.
Want help turning the OWASP LLM Top 10 into controls you can prove? Explore our AI Audit & Oversight service, or schedule a call.
Connect:
(571) 306-0036
© 2026. All rights reserved.
