Join our Newsletter — 33% off our NHI Course

OWASP top 10 for LLMs: what IAM teams need to know

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: OWASP’s 2025 Top 10 for LLM Applications adds new categories for excessive agency, system prompt leakage, vector weaknesses and unbounded consumption, while reworking earlier risks around prompt injection, disclosure and supply chain exposure. The update shows that AI security now hinges on identity, access and control boundaries rather than model quality alone, according to Aembit. Access review assumptions break when nonhuman actors can act, leak and chain decisions inside a single session.

Editorial analysis by NHI Mgmt Group, based on content published by Aembit: “The OWASP Top 10 for LLM Applications (2025): Explained Simply”.

Key questions

Q: What breaks when LLMs can act with excessive agency?

A: The control model breaks when an AI agent can reach more tools, more data or more actions than the task requires.

Q: Why do prompt injection attacks create governance risk for AI agents?

A: Prompt injection creates governance risk because the model often sits in the control path between text input and tool execution.

Q: How should teams govern system prompts in LLM applications?

A: Teams should treat system prompts as configuration, not as a secrecy boundary.

Practitioner guidance

  • Map nonhuman authority boundaries Inventory which tools, data stores and outbound actions each LLM or agent can reach, then remove anything not required for the specific task.
  • Move authorization outside prompts Keep access decisions in deterministic policy systems and treat prompt text as untrusted instruction content, not as a control plane.
  • Restrict agent permissions by task Assign the minimum permissions needed for each workflow, and separate read, write and act capabilities so a single model session cannot pivot broadly.

Bottom line: LLM application risk now sits at the intersection of model behaviour, identity boundaries and tool authority, not just prompt quality or data hygiene.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 21 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 20882
 

Identity, not model quality, is now the primary security boundary for LLM applications. The article makes clear that the most damaging LLM risks emerge when models can read, retrieve and act across trust boundaries. That changes the governance question from how accurate the model is to who or what is allowed to influence or execute actions through it. The practical conclusion is that IAM, PAM and workload identity controls now sit inside the LLM security model, not beside it.

A few things that frame the scale:

  • AI-related credential leaks surged 81.5% year-over-year in 2025, with the surrounding AI infrastructure leaking 5x faster than core LLM providers, according to the State of Secrets Sprawl 2026.

A question worth separating out:

Q: How do organisations know if an LLM deployment is overstepping its authority?

A: Look for models or agents that can reach unrelated tools, perform high-impact actions without approval, or expose internal rules and secrets through normal interaction. Those are signs that authority is too broad and the security boundary is being enforced by the model instead of by policy.

👉 Read our full editorial: OWASP top 10 for LLMs shows identity gaps in agentic AI


This post was modified 21 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.