Law / Frameworks / OWASP LLM Top 10
OWASP LLM Top 10 LLM02:2026Sensitive Information Disclosure
Sensitive information disclosure occurs when an LLM-integrated system exposes confidential, regulated, privileged, or proprietary data through a channel the data subject, controller, or system owner did not authorize. The channel is not only the final answer: tool-call arguments, reasoning traces, retrieved chunks, multimodal output, logs, telemetry, embeddings, and observable inference properties (timing, token length, log-probabilities, confidence, cache-hit behavior) are all disclosure surfaces. Treat each as an output subject to the same classification and redaction rules.OWASP Top 10 for LLM Applications, 2026 edition, August 2026, LLM02:2026
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
The kinds of duty that reach it: security.
- 1
- law
- 1
- place
- 0
- with court rulings behind them
- 1
- not yet in force
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFMEASURE 2.5 The AI system to be deployed is demonstrated to be valid and reliable. Limitations of...
- NIST AI RMFMEASURE 2.6 The AI system is evaluated regularly for safety risks – as identified in the MAP...
- NIST AI 600-1GAI-RISK-04 Data Privacy
- NIST AI 600-1GAI-RISK-09 Information Security
- OWASP Agentic Top 10ASI01 Agent Goal Hijack
- OWASP Agentic Top 10ASI03 Identity and Privilege Abuse
- MIT mitigations2.1 Model & Infrastructure Security
- MIT mitigations2.3 Model Safety Engineering
- NIST Privacy FrameworkPR.PO-P7 Response plans (Incident Response and Business Continuity) and recovery plans...
- NIST Privacy FrameworkPR.PO-P10 A vulnerability management plan is developed and implemented.
- NIST CSF 2.0ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded
- NIST CSF 2.0ID.RA-08 Processes for receiving, analyzing, and responding to vulnerability disclosures are established
A law in force is unmarked; the rest wear their state: not yet in force
AI risk obligations
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| AI Act, Article 15 (accuracy, robustness and cybersecurity) from , in 14 months |
Through its security duty. What it requires |
Excerpts of the OWASP Top 10 for LLM Applications, CC BY-SA 4.0. OWASP GenAI Security Project, OWASP Top 10 for LLM Applications 2026, https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/, licensed CC BY-SA 4.0 (https://creativecommons.org/licenses/by-sa/4.0/). Excerpted: only the first paragraph of each entry's Description is reproduced, verbatim. Every control of the framework.