The OWASP Top 10 for LLM Applications is a curated list of the most critical security threats to LLM and generative AI systems.
AIUC-1 integrates OWASP’s Top 10 for LLM and Generative AI. Certification against AIUC-1:
- Addresses Top Ten threats in requirements and controls
- Strengthens robustness against the threats identified with concrete requirements and controls
- Goes beyond OWASP’s focus on security alone
OWASP Top 10 crosswalks by threat
| OWASP threat | OWASP description | Relevant AIUC-1 requirements |
|---|---|---|
| LLM01:25 - Prompt Injection | This manipulates a large language model (LLM) through crafty inputs, causing unintended actions by the LLM. Direct injections overwrite system prompts, while indirect ones manipulate inputs from external sources. | |
| LLM02:25 - Sensitive Information Disclosure | Sensitive info in LLMs includes PII, financial, health, business, security, and legal data. Proprietary models face risks with unique training methods and source code, critical in closed or foundation models. | |
| LLM03:25 - Supply Chain | LLM supply chains face risks in training data, models, and platforms, causing bias, breaches, or failures. Unlike traditional software, ML risks include third-party pre-trained models and data vulnerabilities. | |
| LLM04:25 - Data and Model Poisoning | Data poisoning manipulates pre-training, fine-tuning, or embedding data, causing vulnerabilities, biases, or backdoors. Risks include degraded performance, harmful outputs, toxic content, and compromised downstream systems. | |
| LLM05:25 - Improper Output Handling | Improper Output Handling involves inadequate validation of LLM outputs before downstream use. Exploits include XSS, CSRF, SSRF, privilege escalation, or remote code execution, which differs from Overreliance. | E009: Monitor third-party accessA004: Protect IP & trade secretsA005: Prevent cross-customer data exposureA006: Prevent PII leakageA007: Prevent IP violationsD001: Prevent hallucinated outputsC003: Prevent harmful outputsC004: Prevent out-of-scope outputsC005: Prevent agent-specific high risk outputsC006: Prevent output vulnerabilitiesB001: Third-party testing of adversarial robustnessB009: Limit output over-exposureB004: Prevent AI endpoint scraping |
| LLM06:25 - Excessive Agency | LLM systems gain agency via extensions, tools, or plugins to act on prompts. Agents dynamically choose extensions and make repeated LLM calls, using prior outputs to guide subsequent actions for dynamic task execution. | |
| LLM07:25 - System Prompt Leakage | System prompt leakage occurs when sensitive info in LLM prompts is unintentionally exposed, enabling attackers to exploit secrets. These prompts guide model behavior but can unintentionally reveal critical data. | |
| LLM08:25 - Vector and Embedding Weaknesses | Vectors and embeddings vulnerabilities in RAG with LLMs allow exploits via weak generation, storage, or retrieval. These can inject harmful content, manipulate outputs, or expose sensitive data, posing significant security risks. | A003: Limit AI agent data accessA004: Protect IP & trade secretsA005: Prevent cross-customer data exposureA006: Prevent PII leakageD003: Restrict unsafe tool callsB001: Third-party testing of adversarial robustnessB002: Detect adversarial inputB004: Prevent AI endpoint scrapingB006: Prevent unauthorized AI agent actionsB009: Limit output over-exposure |
| LLM09:25 - Misinformation | LLM misinformation occurs when false and credible outputs mislead users, risking security breaches, reputational harm, and legal liability, making it a critical vulnerability for reliant applications. | |
| LLM10:25 - Unbounded Consumption | Unbounded Consumption occurs when LLMs generate outputs from inputs, relying on inference to apply learned patterns and knowledge for relevant responses or predictions, making it a key function of LLMs. | E010: Establish AI acceptable use policyE009: Monitor third-party accessB005: Implement real-time input filteringB002: Detect adversarial inputB004: Prevent AI endpoint scrapingD003: Restrict unsafe tool callsE015: Log AI system activityA003: Limit AI agent data accessB006: Prevent unauthorized AI agent actionsB007: Enforce user access privileges to AI systems |
37.782274° N -122.392147° WFIG. A (SITE INDEX)
Artificial Intelligence Underwriting Company
CodeStructural unita.AIUC-1 requirements for agent data, privacy, security, safety, reliability, accountability, and societal risk.b.Evidence templates for technical implementation, legal policy, operational practice, and third-party evaluation.c.Crosswalks to AI regulations, standards, and security frameworks.d.Quarterly updates shaped by enterprise adoption, risk, regulation, and community input.
I. Standard
II. Learn
III. Office
100© AIUC — ALL RIGHTS RESERVED