TL;DR: OWASP’s 2025 Top 10 for LLM Applications adds new categories for excessive agency, system prompt leakage, vector weaknesses and unbounded consumption, while reworking earlier risks around prompt injection, disclosure and supply chain exposure. The update shows that AI security now hinges on identity, access and control boundaries rather than model quality alone, according to Aembit. Access review assumptions break when nonhuman actors can act, leak and chain decisions inside a single session.
Editorial analysis by NHI Mgmt Group, based on content published by Aembit: “The OWASP Top 10 for LLM Applications (2025): Explained Simply”.
Key questions
Q: What breaks when LLMs can act with excessive agency?
A: The control model breaks when an AI agent can reach more tools, more data or more actions than the task requires.
Q: Why do prompt injection attacks create governance risk for AI agents?
A: Prompt injection creates governance risk because the model often sits in the control path between text input and tool execution.
Q: How should teams govern system prompts in LLM applications?
A: Teams should treat system prompts as configuration, not as a secrecy boundary.
Practitioner guidance
- Map nonhuman authority boundaries Inventory which tools, data stores and outbound actions each LLM or agent can reach, then remove anything not required for the specific task.
- Move authorization outside prompts Keep access decisions in deterministic policy systems and treat prompt text as untrusted instruction content, not as a control plane.
- Restrict agent permissions by task Assign the minimum permissions needed for each workflow, and separate read, write and act capabilities so a single model session cannot pivot broadly.
Bottom line: LLM application risk now sits at the intersection of model behaviour, identity boundaries and tool authority, not just prompt quality or data hygiene.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Identity, not model quality, is now the primary security boundary for LLM applications. The article makes clear that the most damaging LLM risks emerge when models can read, retrieve and act across trust boundaries. That changes the governance question from how accurate the model is to who or what is allowed to influence or execute actions through it. The practical conclusion is that IAM, PAM and workload identity controls now sit inside the LLM security model, not beside it.
A few things that frame the scale:
- AI-related credential leaks surged 81.5% year-over-year in 2025, with the surrounding AI infrastructure leaking 5x faster than core LLM providers, according to the State of Secrets Sprawl 2026.
A question worth separating out:
Q: How do organisations know if an LLM deployment is overstepping its authority?
A: Look for models or agents that can reach unrelated tools, perform high-impact actions without approval, or expose internal rules and secrets through normal interaction. Those are signs that authority is too broad and the security boundary is being enforced by the model instead of by policy.
👉 Read our full editorial: OWASP top 10 for LLMs shows identity gaps in agentic AI