Law / Frameworks / OWASP LLM Top 10
OWASP Top 10 for LLM Applications
Below are its 10 controls in the framework's own order, and under each one the laws we track that bear on it. Each mapping is our reading that a law bears on a control, never a finding that running the control meets the law.
Where the law lands in the framework
5of 10 controls have law165laws115places
Of these laws, 143 are in force and 22 not yet in force.
- in force
- not yet in force
- blocked by a court
- proposed
- no law we track
Read through the kinds of duty each AI and scraping law we track carries, counting a kind of duty only where the law's own requirement lines, as read against the NIST AI Risk Management Framework, bear it out.
| Control | What it says | Laws, by state | Laws | Places | Not yet in force |
|---|---|---|---|---|---|
| LLM01:2026 | Prompt Injection 1 law, 1 not yet in force | 1 | 1 | 1 | |
| LLM02:2026 | Sensitive Information Disclosure 1 law, 1 not yet in force | 1 | 1 | 1 | |
| LLM03:2026 | Excessive Agency 164 laws, 21 not yet in force | 164 | 115 | 21 | |
| LLM04:2026 | Supply Chain 1 law, 1 not yet in force | 1 | 1 | 1 | |
| LLM05:2026 | Data and Model Poisoning 1 law, 1 not yet in force | 1 | 1 | 1 | |
| LLM06:2026 | Unbounded Consumption no law we track | no law we track | |||
| LLM07:2026 | Misinformation no law we track | no law we track | |||
| LLM08:2026 | Hidden Context Exposure no law we track | no law we track | |||
| LLM09:2026 | Vector and Embedding Weaknesses no law we track | no law we track | |||
| LLM10:2026 | Improper Output Handling no law we track | no law we track | |||
Where the law and the framework part
5 of the 10 controls have no law we track under them.
Kinds of duty this framework has no control for: age verification, attribution, biometric, breach notice, consent, content labelling, contract terms, data subject rights, design code, disclosure, DPIA, licensing, prohibition, reporting, retention, TDM, transfer.
The framework's text
Excerpts of the OWASP Top 10 for LLM Applications, CC BY-SA 4.0. OWASP GenAI Security Project, OWASP Top 10 for LLM Applications 2026, https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/, licensed CC BY-SA 4.0 (https://creativecommons.org/licenses/by-sa/4.0/). Excerpted: only the first paragraph of each entry's Description is reproduced, verbatim.
Read it from the publisher: genai.owasp.org