Law / Frameworks / OWASP LLM Top 10

OWASP LLM Top 10 LLM01:2026Prompt Injection

A prompt-injection vulnerability occurs when input to a large language model (LLM), whether direct user input, retrieved content, tool output, image, audio, or video content, intermediate reasoning, or persistent memory, alters the model's behavior in ways the application developer did not intend. LLMs make no architectural distinction between "instructions" and "data" (both are tokens on the same stream), so there is no clean equivalent to parameterized queries (NCSC, 2025). Inputs need not be human-readable, need not arrive directly from a user, and need not be visible in the rendered interface to influence the model.OWASP Top 10 for LLM Applications, 2026 edition, August 2026, LLM01:2026

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

The kinds of duty that reach it: security.

1
law
1
place
0
with court rulings behind them
1
not yet in force

The same ground elsewhere linked through the kinds of duty both controls are mapped from

A law in force is unmarked; the rest wear their state: not yet in force

AI risk obligations

1 law, 1 place
PlaceLawHow it reaches this control
European Union AI Act, Article 15 (accuracy, robustness and cybersecurity) from , in 14 months

Through its security duty. What it requires

Excerpts of the OWASP Top 10 for LLM Applications, CC BY-SA 4.0. OWASP GenAI Security Project, OWASP Top 10 for LLM Applications 2026, https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/, licensed CC BY-SA 4.0 (https://creativecommons.org/licenses/by-sa/4.0/). Excerpted: only the first paragraph of each entry's Description is reproduced, verbatim. Every control of the framework.