Law / Frameworks / OWASP LLM Top 10

OWASP LLM Top 10 LLM03:2026Excessive Agency

An LLM-based system is often granted a degree of agency by its developer: the ability to call functions or interface with other systems via tools (also called extensions, plugins, or skills by different vendors) to undertake actions in response to a prompt. An LLM agent may also select which tool to invoke dynamically, based on the input prompt or prior LLM output. Agent-based systems will typically make repeated calls to an LLM using output from previous invocations to ground and direct subsequent invocations.OWASP Top 10 for LLM Applications, 2026 edition, August 2026, LLM03:2026

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

The kinds of duty that reach it: access restriction, governance.

164
laws
115
places
0
with court rulings behind them
21
not yet in force

The same ground elsewhere linked through the kinds of duty both controls are mapped from

A law in force is unmarked; the rest wear their state: not yet in force

  • Afghanistan
  • Alabama
  • Alaska
  • Albania
  • Algeria
  • Andorra
  • Arkansas
  • Austria
  • Bahamas
  • Bangladesh
  • Belarus
  • Belgium
  • Belize
  • Benin
  • Bermuda
  • Bhutan
  • Bolivia
  • Brazil
  • Bulgaria
  • Burkina Faso
  • Cabo Verde
  • California
  • Cameroon
  • Colombia
  • Colorado
  • Comoros
  • Cook Islands
  • Costa Rica
  • Croatia
  • Cuba
  • Czech Republic
  • Côte d'Ivoire
  • Denmark
  • Egypt
  • El Salvador
  • Eritrea
  • Ethiopia
  • European Union
  • Finland
  • Gabon
  • Gambia
  • Georgia
  • Georgia
  • Germany
  • Ghana
  • Greece
  • Guatemala
  • Guinea
  • Honduras
  • Hungary
  • Idaho
  • Illinois
  • Indiana
  • Jamaica
  • Jordan
  • Kentucky
  • Kiribati
  • Kyrgyzstan
  • Latvia
  • Libya
  • Lithuania
  • Louisiana
  • Maine
  • Mali
  • Malta
  • Mauritania
  • Mexico
  • Michigan
  • Minnesota
  • Mississippi
  • Monaco
  • Montana
  • Montenegro
  • Nauru
  • Nepal
  • Nevada
  • Nicaragua
  • North Carolina
  • North Dakota
  • Panama
  • Paraguay
  • Pennsylvania
  • Peru
  • Poland
  • Qatar
  • Romania
  • Russia
  • Samoa
  • San Marino
  • Sao Tome and Principe
  • Senegal
  • Serbia
  • Slovenia
  • South Carolina
  • South Korea
  • South Sudan
  • State of Palestine
  • Suriname
  • Sweden
  • Switzerland
  • Taiwan
  • Togo
  • Tonga
  • Trinidad and Tobago
  • Turkey
  • Tuvalu
  • Uruguay
  • Utah
  • Vanuatu
  • Vatican City
  • Venezuela
  • Vietnam
  • Wyoming
  • Zambia
  • Zimbabwe

Computer misuse

112 laws, 99 places
PlaceLawHow it reaches this control
Afghanistan Penal Code, Part Twelve, Chapter One (Cyber Crimes and Punishment)

Through its access restriction duty. What it requires

Alabama Alabama Digital Crime Act, Computer Tampering

Through its access restriction duty. What it requires

Alaska Criminal mischief in the fourth degree, unauthorized computer access

Through its access restriction duty. What it requires

Alaska Criminal use of a computer

Through its access restriction duty. What it requires

Alaska Theft of services, unauthorized use of a computer system

Through its access restriction duty. What it requires

Algeria Code pénal, atteintes aux systèmes de traitement automatisé de données

Through its access restriction duty. What it requires

Andorra Penal Code, Attacks on Information Systems

Through its access restriction duty. What it requires

Arkansas Computer fraud

Through its access restriction duty. What it requires

Arkansas Computer trespass

Through its access restriction duty. What it requires

Arkansas Unlawful interference with access to computers; unlawful use or access of computers

Through its access restriction duty. What it requires

Show the other 102 laws
Austria StGB Sections 118a and 126a to 126c, Computer-Misuse Offenses

Through its access restriction duty. What it requires

Bahamas Computer Misuse Act 2003, unauthorised access, modification and interception offences

Through its access restriction duty. What it requires

Bangladesh Cyber Security Act, 2026, unauthorised access to a computer system

Through its access restriction duty. What it requires

Belarus Criminal Code, Crimes Against Computer Security

Through its access restriction duty. What it requires

Belgium Code pénal, Livre II, articles 524 à 527, accès non autorisé dans un système informatique

Through its access restriction duty. What it requires

Belize Cybercrime Act, illegal access to a computer system

Through its access restriction duty. What it requires

Benin Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre VI (cybercriminalité), atteintes aux réseaux et systèmes d'information

Through its access restriction duty. What it requires

Bermuda Computer Misuse Act 1996, unauthorised access and modification offences

Through its access restriction duty. What it requires

Bhutan Information, Communications and Media Act of Bhutan 2018, unauthorized access and tampering with computer systems

Through its access restriction duty. What it requires

Bolivia Código Penal, Alteración, Acceso y Uso Indebido de Datos Informáticos

Through its access restriction duty. What it requires

Brazil Penal Code Art. 154-A, Invasion of a Computing Device

Through its access restriction duty. What it requires

Bulgaria Criminal Code (Nakazatelen kodeks), Art. 319a, Unauthorized Access to an Information System

Through its access restriction duty. What it requires

Burkina Faso Loi n°025-2018/AN du 31 mai 2018 portant Code pénal, computer and data systems offenses (Livre VII, Titre I, Chapitre 1)

Through its access restriction duty. What it requires

Cabo Verde Cybercrime Law, Unauthorised Access to a Computer System

Through its access restriction duty. What it requires

Cameroon Loi n°2010/012 du 21 décembre 2010 relative à la cybersécurité et à la cybercriminalité au Cameroun, articles 68-69 (accès frauduleux)

Through its access restriction duty. What it requires

Colombia Código Penal, Acceso Abusivo a un Sistema Informático

Through its access restriction duty. What it requires

Comoros Penal Code, unauthorized access to an information system

Through its access restriction duty. What it requires

Costa Rica Código Penal, artículo 231, Espionaje informático

Through its access restriction duty. What it requires

Croatia Kazneni zakon, Computer Crime Chapter (Arts. 266-273)

Through its access restriction duty. What it requires

Cuba Código Penal (Ley 151/2022), offenses against telecommunications and ICT security

Through its access restriction duty. What it requires

Czech Republic Criminal Code Section 230, Unauthorized Access to a Computer System

Through its access restriction duty. What it requires

Côte d'Ivoire Cybercrime Act, unauthorized access to an information system

Through its access restriction duty. What it requires

Egypt Law No. 175 of 2018 on Anti-Cyber and Information Technology Crimes

Through its access restriction duty. What it requires

El Salvador Ley de Propiedad Intelectual, elusión de medidas tecnológicas efectivas

Through its access restriction duty. What it requires

El Salvador Ley Especial contra los Delitos Informáticos y Conexos, acceso indebido a sistemas informáticos

Through its access restriction duty. What it requires

Eritrea Penal Code of the State of Eritrea, Unauthorized Use of a Computer from a date not yet set

Through its access restriction duty. What it requires

Ethiopia Computer Crime Proclamation

Through its access restriction duty. What it requires

Finland Rikoslaki Chapter 38, Tietomurto and törkeä tietomurto (Computer Break-in and Aggravated Computer Break-in)

Through its access restriction duty. What it requires

Gabon Loi n°027/2023, infractions et sanctions informatiques

Through its access restriction duty. What it requires

Gambia Information and Communications Act, 2009, Computer Misuse and Cyber Crime part

Through its access restriction duty. What it requires

Georgia Criminal Code, unauthorised access and interference with computer data and systems

Through its access restriction duty. What it requires

Georgia Georgia Computer Systems Protection Act, computer theft, trespass, invasion of privacy, forgery, password disclosure from a date not yet set

Through its access restriction duty. What it requires

Ghana Cybersecurity Act, Unlawful Access

Through its access restriction duty. What it requires

Ghana Electronic Transactions Act, Cyber Offences

Through its access restriction duty. What it requires

Greece Penal Code Article 370C (370Γ), Violation of Computer Data and Program Secrets

Through its access restriction duty. What it requires

Greece Penal Code Article 370D (370Δ), Access to an Information System in Breach of a Prohibition or Security Measure

Through its access restriction duty. What it requires

Guatemala Código Penal, Decreto 17-73, Arts. 274 'A' a 274 'G' (Delitos Informáticos)

Through its access restriction duty. What it requires

Guinea Loi n° L/2016/037/AN portant Cybersécurité et Protection des Données à Caractère Personnel, titre relatif aux infractions informatiques (cybercriminalité)

Through its access restriction duty. What it requires

Honduras Código Penal, seguridad de las redes y de los sistemas informáticos

Through its access restriction duty. What it requires

Hungary Büntető Törvénykönyv (Criminal Code), Sections 423-424, Violation of Information Systems or Data

Through its access restriction duty. What it requires

Idaho Computer crime (unauthorized access, use, or alteration)

Through its access restriction duty. What it requires

Jamaica Cybercrimes Act, 2015, unauthorised access to computer program or data

Through its access restriction duty. What it requires

Jordan Cybercrime Law, Unauthorized Access to Information Systems

Through its access restriction duty. What it requires

Kentucky Kentucky Unlawful Access to a Computer

Through its access restriction duty. What it requires

Kiribati Cybercrime Act 2021, unauthorised access from a date not yet set

Through its access restriction duty. What it requires

Kyrgyzstan Criminal Code, unauthorized access to computer information

Through its access restriction duty. What it requires

Latvia Krimināllikums Sections 241, 243, 244, Automated Data Processing System Offences

Through its access restriction duty. What it requires

Libya Law No. 5 of 2022 on Combating Cybercrimes, unauthorised access and system interference

Through its access restriction duty. What it requires

Lithuania Criminal Code Arts. 196-198 and 198-1, Computer Misuse and Unauthorised Access Offenses

Through its access restriction duty. What it requires

Louisiana Louisiana Computer Tampering, unauthorized access and exceeding authorization

Through its access restriction duty. What it requires

Maine Aggravated criminal invasion of computer privacy

Through its access restriction duty. What it requires

Maine Criminal invasion of computer privacy

Through its access restriction duty. What it requires

Mali Loi n° 2019-056, accès et maintien frauduleux à un système d'information

Through its access restriction duty. What it requires

Mauritania Loi n° 2016-007, accès non autorisé à un système informatique

Through its access restriction duty. What it requires

Mexico Código Penal Federal, Unauthorised Access to Computer Systems and Equipment (Arts. 211 bis 1 to 211 bis 7)

Through its access restriction duty. What it requires

Mexico Ley Federal del Derecho de Autor, Technological Protection Measures and Circumvention (Arts. 114 Bis, 232 Bis)

Through its access restriction duty. What it requires

Michigan Fraudulent Access to Computers, Computer Systems, and Computer Networks Act

Through its access restriction duty. What it requires

Mississippi Mississippi Computer Crimes and Identity Theft Act, core offenses

Through its access restriction duty. What it requires

Monaco Code Pénal Arts. 389-1 to 389-9, Unauthorized Access, System Interference and Data Damage

Through its access restriction duty. What it requires

Montenegro Criminal Code of Montenegro, Unauthorised Access to a Computer System

Through its access restriction duty. What it requires

Nauru Cybercrime Act 2015, illegal access to a protected computer

Through its access restriction duty. What it requires

Nepal Electronic Transactions Act, 2063, unauthorised access to computer materials

Through its access restriction duty. What it requires

Nevada Unlawful acts regarding computers, private action and enforcement

Through its access restriction duty. What it requires

Nicaragua Ley No. 1042, interference with and damage to computer systems, as reformed by Ley No. 1219

Through its access restriction duty. What it requires

Nicaragua Ley No. 1042, unauthorized access to computer systems

Through its access restriction duty. What it requires

North Carolina North Carolina Computer-Related Crime Act (unauthorized access and computer trespass)

Through its access restriction duty. What it requires

North Dakota Computer fraud and computer crime

Through its access restriction duty. What it requires

Panama Código Penal, Delitos contra la Seguridad Informática

Through its access restriction duty. What it requires

Paraguay Código Penal, arts. 146 b y 174 b, introducidos por la Ley N° 4439/2011, acceso indebido a datos y a sistemas informáticos

Through its access restriction duty. What it requires

Pennsylvania Unlawful use of computer and other computer crimes (hacking and similar offenses)

Through its access restriction duty. What it requires

Peru Decreto Legislativo 1700, illicit trafficking of computer data (art. 12-A of Ley 30096)

Through its access restriction duty. What it requires

Peru Ley 30096, unauthorized access and data/system integrity offenses

Through its access restriction duty. What it requires

Poland Kodeks karny, Unauthorized Access to Information and Computer-Misuse Offenses

Through its access restriction duty. What it requires

Qatar Cybercrime Prevention Law, unauthorised access

Through its access restriction duty. What it requires

Romania Cod penal, Art. 360-366, Infracțiuni contra siguranței și integrității sistemelor și datelor informatice (Offences Against the Security and Integrity of Computer Systems and Data)

Through its access restriction duty. What it requires

Russia Criminal Code Article 272, Unauthorized Access to Computer Information

Through its access restriction duty. What it requires

Russia Criminal Code Article 274, Violation of Rules for Operating Computer-Information Storage, Processing or Transmission Systems

Through its access restriction duty. What it requires

Samoa Crimes Act 2013, computer-access and interference offences

Through its access restriction duty. What it requires

San Marino Computer Crimes Law, Unlawful Access to Computer or Telematics Systems

Through its access restriction duty. What it requires

Senegal Loi n° 2008-11 du 25 janvier 2008 sur la Cybercriminalité, unauthorized computer-system access (Penal Code arts. 431-8 to 431-9)

Through its access restriction duty. What it requires

Serbia Criminal Code, Offences Against the Security of Computer Data

Through its access restriction duty. What it requires

Slovenia Kazenski zakonik (KZ-1, Criminal Code), Art. 221, Napad na informacijski sistem (Attack on an Information System)

Through its access restriction duty. What it requires

South Carolina South Carolina Computer Crime Act

Through its access restriction duty. What it requires

South Sudan National Communication Act, 2012, confidentiality and unauthorised interception of communications

Through its access restriction duty. What it requires

South Sudan Penal Code Act, 2008, computer and electronic related offences

Through its access restriction duty. What it requires

State of Palestine Law by Decree No. 10 of 2018 on Cybercrime, Unauthorised Access and Computer Interference

Through its access restriction duty. What it requires

Suriname Wetboek van Strafrecht, Hacking and Denial of Access (arts. 187b-187c)

Through its access restriction duty. What it requires

Sweden Brottsbalken 4 kap. 9 c §, Unauthorized Computer Access (Dataintrång)

Through its access restriction duty. What it requires

Switzerland Swiss Criminal Code, Unauthorised Access to and Interference with Data Processing Systems

Through its access restriction duty. What it requires

Taiwan Criminal Code, Offenses Against Computer Security

Through its access restriction duty. What it requires

Togo Loi n° 2018-026, accès et maintien frauduleux à un système informatique

Through its access restriction duty. What it requires

Tonga Computer Crimes Act 2003, unauthorised access

Through its access restriction duty. What it requires

Trinidad and Tobago Computer Misuse Act 2000, Unauthorised Access

Through its access restriction duty. What it requires

Turkey Turkish Penal Code, Information System Crimes

Through its access restriction duty. What it requires

Tuvalu Tuvalu Telecommunications Corporation Act 1993, offences and penalties

Through its access restriction duty. What it requires

Uruguay Código Penal arts. 297 bis, 297 ter, 297 quater, 358 quater, and 358 quinquies, computer-offence provisions inserted by Ley N° 20.327

Through its access restriction duty. What it requires

Vanuatu Cybercrime Act 2021, computer-access and interference offences

Through its access restriction duty. What it requires

Vatican City Unauthorised access to a protected computer or telematic system (Legge N. DXXXI, arts. 158 ter-158 quater)

Through its access restriction duty. What it requires

Venezuela Ley Especial contra los Delitos Informáticos, unauthorized access and sabotage of systems (Arts. 6-11)

Through its access restriction duty. What it requires

Wyoming Crimes against computer users (bare without-authorization test)

Through its access restriction duty. What it requires

Zambia Cyber Crimes Act, 2025, unauthorised access to computer system and data

Through its access restriction duty. What it requires

Zimbabwe Cyber and Data Protection Act, Insertion of Computer-Misuse Offences into the Criminal Law Code

Through its access restriction duty. What it requires

AI risk obligations

14 laws, 8 places
PlaceLawHow it reaches this control
El Salvador Resolución ANIA 0001/2025, registro obligatorio para decisiones consecuenciales

Through its governance duty. What it requires

European Union AI Act, Article 10 (data and data governance) from , in 14 months

Through its governance duty. What it requires

European Union AI Act, Article 111(2) (2030 compliance deadline for public-authority-intended systems) from , in 3.8 years

Through its governance duty. What it requires

European Union AI Act, Article 14 (human oversight) from , in 14 months

Through its governance duty. What it requires

European Union AI Act, Article 26(1) to (5) (deployer use, human oversight, input data and monitoring) from , in 14 months

Through its governance duty. What it requires

European Union AI Act, Article 26(10) (post-remote biometric identification authorisation) from , in 14 months

Through its governance duty. What it requires

European Union AI Act, Article 6(3) and (4) (narrow-task derogation from Annex III high-risk classification) from , in 14 months

Through its governance duty. What it requires

European Union AI Act, Article 9 (risk management system) from , in 14 months

Through its governance duty. What it requires

Indiana Downcoding of Health Benefits Claims, automated and AI decision-making (House Enrolled Act 1271, 2026)

Through its governance duty. What it requires

Kyrgyzstan Digital Code, Chapter 23: AI system design and risk-management obligations

Through its governance duty. What it requires

Show the other 4 laws
Montana Right to Compute Act (SB 212, 2025), critical AI infrastructure risk management duty

Through its governance duty. What it requires

South Korea AI Framework Act, Article 34 (business-operator duties for high-impact AI)

Through its governance duty. What it requires

Vietnam Law on Artificial Intelligence, risk classification and conformity assessment

Through its governance duty. What it requires

Database right

14 laws, 14 places
PlaceLawHow it reaches this control
Algeria Ordonnance n° 03-05, protection des bases de données

Through its access restriction duty. What it requires

Czech Republic Autorský zákon Sections 88-94, Sui Generis Database Right

Through its access restriction duty. What it requires

Ethiopia Copyright and Neighbouring Rights Protection Proclamation, Database Protection

Through its access restriction duty. What it requires

Gabon Loi n°1/87, protection des recueils et compilations

Through its access restriction duty. What it requires

Guatemala Ley de Derecho de Autor y Derechos Conexos, Decreto 33-98 (compilations, databases, and technological measures)

Through its access restriction duty. What it requires

Latvia Autortiesību likums Chapter IX, Sui Generis Database Right

Through its access restriction duty. What it requires

Show the other 4 laws
Poland Ustawa o ochronie baz danych, Sui Generis Database Right

Through its access restriction duty. What it requires

Sao Tome and Principe Decreto-Lei n.º 02/2017, protecção de compilações e exclusão das notícias do dia

Through its access restriction duty. What it requires

AI governance

11 laws, 8 places
PlaceLawHow it reaches this control
California Transparency in Frontier Artificial Intelligence Act (SB 53)

Through its governance duty. What it requires

European Union AI Act, Article 12 (record-keeping) from , in 14 months

Through its governance duty. What it requires

European Union AI Act, Article 19 (automatically generated logs) from , in 14 months

Through its governance duty. What it requires

European Union AI Act, Article 21(2) (competent authority access to automatically generated logs) from , in 14 months

Through its governance duty. What it requires

European Union AI Act, Article 26(6) (deployer log-keeping) from , in 14 months

Through its governance duty. What it requires

Germany Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz (KI-MIG), AI Market Surveillance and Innovation Promotion Act

Through its governance duty. What it requires

Hungary Act LXXV of 2025 on the Domestic Implementation of the EU AI Regulation

Through its governance duty. What it requires

Illinois Artificial Intelligence Safety Measures Act from , in 3 months

Through its governance duty. What it requires

Russia Federal Law No. 243-FZ, Article 8, Duties of Sovereign and National Foundation Model Developers from , in 5 months

Through its governance duty. What it requires

Vanuatu Digital Transformation Act 2025, ICT service permit for AI and AI-related data services

Through its governance duty. What it requires

Show the other 1 law
Vatican City Guidelines on Artificial Intelligence of Vatican City State (Decree No. DCCII)

Through its governance duty. What it requires

AI sector rules

7 laws, 7 places
PlaceLawHow it reaches this control
Alabama SB 63 (2026), Artificial Intelligence in Health Insurance Prior Authorization from , in 2 days

Through its governance duty. What it requires

Colorado Amended Regulation 10-1-1 (2025), Governance and Risk Management Framework for Insurers' Use of External Consumer Data and Information Sources, Algorithms, and Predictive Models

Through its governance duty. What it requires

Georgia Private Review Agent Artificial Intelligence Coverage Determinations Act (SB 444) from , in 3 months

Through its governance duty. What it requires

Maine Use of artificial intelligence in therapy or psychotherapy services from a date not yet set

Through its governance duty. What it requires

Minnesota Utilization Review, AI-Only Adverse Determination Prohibition from , in 3 months

Through its governance duty. What it requires

Nevada AB 406 (2025), licensed provider restriction on direct clinical use of AI

Through its governance duty. What it requires

Utah Health Insurance Preauthorization AI Disclosure (SB 319, 2026 General Session) from , in 3 months

Through its governance duty. What it requires

AI prohibited practices

1 law, 1 place
PlaceLawHow it reaches this control
Denmark Lov nr. 467 af 14. maj 2025, National Competent Authorities and Article 5 Enforcement

Through its governance duty. What it requires

AI training data

1 law, 1 place
PlaceLawHow it reaches this control
European Union AI Act, Article 53 (obligations for providers of general-purpose AI models)

Through its governance duty. What it requires

AI transparency

1 law, 1 place
PlaceLawHow it reaches this control
Jamaica Practice Direction No. 1 of 2025, Use of Generative Artificial Intelligence in Court Proceedings

Through its governance duty. What it requires

Personal data

1 law, 1 place
PlaceLawHow it reaches this control
Colombia Código Penal, Violación de Datos Personales

Through its access restriction duty. What it requires

Excerpts of the OWASP Top 10 for LLM Applications, CC BY-SA 4.0. OWASP GenAI Security Project, OWASP Top 10 for LLM Applications 2026, https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/, licensed CC BY-SA 4.0 (https://creativecommons.org/licenses/by-sa/4.0/). Excerpted: only the first paragraph of each entry's Description is reproduced, verbatim. Every control of the framework.