OWASP updates 2026 LLM security guidance
The OWASP GenAI Security Project released the 2026 Top 10 for LLM Applications, updating its flagship guidance for identifying and mitigating critical risks in applications powered by large language models. The project said the new edition surpassed 10,000 downloads within its first 48 hours as organizations move AI systems from experimentation into production.
The 2026 edition was built with contributions from hundreds of AI security experts and draws on thousands of real-world AI security incidents. It includes updated rankings, broader threat coverage and expanded mappings to NIST, MITRE ATLAS, CWE and the project’s Top 10 for Agentic Applications.
OWASP also added the Agent Control Standard to support runtime enforcement for agentic AI systems, alongside an expanded AI Security Solutions Directory and a GenAI Security Industry Framework Crosswalk. The project said it has surpassed 30,000 members on LinkedIn and added F5, WitnessAI, Evoke Security and Mondoo Inc. as new sponsors.