TL;DR: OWASP’s 2025 Top 10 for LLM applications raises prompt injection, sensitive information disclosure, excessive agency, system prompt leakage, RAG and embedding risks, misinformation, and unbounded consumption as the defining GenAI threats, according to Lasso Security. AI governance now has to control runtime behaviour, data leakage, and decision scope, not just model deployment.
Editorial analysis by NHI Mgmt Group, based on content published by Lasso Security: “OWASP Top 10 for LLM Applications & Generative AI: Key Updates for 2025”.
Key questions
Q: How should security teams handle prompt injection in production LLM applications?
A: Security teams should treat prompt injection as a runtime control issue, not a content-moderation problem.
Q: Why does excessive agency change how organisations govern GenAI?
A: Because the risk moves from what the model says to what the model can do.
Q: What breaks when retrieval data is not governed in RAG systems?
A: The model can treat poisoned or low-trust content as if it were authoritative context.
Practitioner guidance
- Tighten prompt boundary controls Separate system instructions from user and retrieved content, and test whether untrusted text can influence tool use or policy output.
- Limit agentic authority Define explicit action scopes, approval gates, and tool permissions before enabling any LLM to initiate workflow steps.
- Govern retrieval write paths Restrict who can add or modify corpus content, and review ingestion pipelines for poisoning, drift, and stale source material.
Bottom line: OWASP’s 2025 update treats LLM risk as a runtime governance problem, not just a model safety problem.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Prompt injection is now an identity control problem as much as an application security problem. Once a model can be steered through untrusted input, the real failure is that the system accepted attacker-authored language inside a trusted decision path. That makes input trust, instruction separation, and retrieval hygiene governance issues, not just model-tuning issues. Practitioners should treat prompt handling as part of access control design.
A few things that frame the scale:
- 98% of companies plan to deploy even more AI agents within the next 12 months, despite documented rogue behaviour in 80% of current deployments, according to AI Agents: The New Attack Surface report.
- Only 44% of organisations have implemented any policies to govern AI agents, even though 92% say that governing them is critical to enterprise security.
A question worth separating out:
Q: How should organisations govern RAG-based AI workflows?
A: Organisations should govern retrieval sources, indexing pipelines, and embedding stores as part of the application’s trust chain. If malicious or low-quality content can enter retrieval, it can steer model outputs and downstream decisions. The practical test is whether the model can be influenced by content it should never have trusted in the first place.
👉 Read our full editorial: OWASP's 2025 LLM risk update raises the bar on AI governance
OWASP’s 2025 LLM update shows that GenAI governance has moved from model approval to runtime control. The article’s risk list is not a collection of isolated issues. It describes a class of systems where data, instructions, retrieval, and action all intersect in the same execution path. Practitioners should treat that as a control-model change, not a feature update.
A few things that frame the scale:
- AI-related credential leaks surged 81.5% year-over-year in 2025, with the surrounding AI infrastructure leaking 5x faster than core LLM providers, according to the State of Secrets Sprawl 2026.
- According to Gartner, worldwide spending on generative AI is set to reach $644 billion in 2025, a nearly 77% year-over-year increase.
A question worth separating out:
Q: How do organisations know whether LLM access controls are actually working?
A: They should verify that every request is evaluated with identity context, that tool access is logged, and that rephrased prompts cannot reach data outside the caller's scope. If a user can change phrasing and still cross an access boundary, the control is not working as intended.
👉 Read our full editorial: OWASP's 2025 LLM risk update raises the bar on AI governance