OWASP Top 10 for LLMs
A community list of the most critical security risks specific to LLM applications.
The OWASP Top 10 for Large Language Models is a community-maintained list of the ten most critical security risks in LLM-powered applications. It covers prompt injection, insecure output handling, training data poisoning, model denial-of-service, sensitive information disclosure, and insecure plugin design, among others. On AIF-C01, it is the industry baseline for responsible AI security and is distinct from the classic OWASP Web Application Top 10. When using Amazon Bedrock, controls such as Guardrails, IAM policies, and VPC endpoints help mitigate several of these LLM-specific risks.
PlayPrepHQ study notes are written and reviewed against primary exam sources. How we create & review content →