Blank white background with no objects or features visible.

TrueFoundry Named Frost & Sullivan's 2026 Global Transformational Innovation Leader. Read report

Découvrez TrueForge : l'infrastructure d'agents open-source et indépendante des fournisseurs. Réduisez vos coûts de 50%. Explorer maintenant→

OWASP LLM Top 10 (2025): Which Risks a Gateway Actually Fixes

Par Ashish Dubey

Published: September 22, 2026

⚡ TL;DR
  • The current list is the OWASP Top 10 for LLM Applications 2025, from the OWASP GenAI Security Project. It replaced the 2023/24 v1.1 list; four entries are new or renamed.
  • It is a risk taxonomy, not a control checklist. Each risk has a natural home - the gateway, the application, the RAG pipeline, the build process - and a control in the wrong place is how teams get coverage on paper and none in production.
  • An AI gateway squarely addresses four: prompt injection, sensitive information disclosure, excessive agency, and unbounded consumption. It partly helps with three more and cannot touch the rest.
  • “OWASP LLM Top 10 compliance” from a single product does not exist. Data and model poisoning and vector weaknesses are not inference-time problems.
  • TrueFoundry’s guardrails run on four hooks - LLM input, LLM output, mcp_pre_tool, mcp_post_tool - which is the part of the map a gateway can honestly claim.

What the OWASP LLM Top 10 actually is

The OWASP Top 10 for Large Language Model Applications is a consensus list of the most critical security risks in LLM-backed software, maintained by the OWASP GenAI Security Project. The current version is the 2025 list at genai.owasp.org/llm-top-10. The v1.1 list from 2023/24 is still archived there and still widely quoted - so if a post mentions Model Theft or Overreliance, it is describing the retired version.

The 2025 list as OWASP publishes it:

ID Risk In one line
LLM01 Prompt Injection User prompts alter the model’s behaviour or output in unintended ways
LLM02 Sensitive Information Disclosure Private data leaks through the model or the surrounding application
LLM03 Supply Chain Compromised models, datasets, packages, or adapters in your stack
LLM04 Data and Model Poisoning Pre-training, fine-tuning, or embedding data is tampered with
LLM05 Improper Output Handling Model output passed downstream without validation or sanitisation
LLM06 Excessive Agency More autonomy, permission, or functionality granted than is needed
LLM07 System Prompt Leakage Instructions meant to stay internal are exposed to the user
LLM08 Vector and Embedding Weaknesses Flaws in how embeddings are generated, stored, and retrieved
LLM09 Misinformation Confident, wrong output that systems or people act on
LLM10 Unbounded Consumption Uncontrolled inference driving cost, denial of service, or extraction

What changed shows where attention moved. System Prompt Leakage and Vector and Embedding Weaknesses are new. Model Denial of Service became the broader Unbounded Consumption. Insecure Plugin Design folded into supply chain and excessive agency as tooling settled around protocols like MCP. Model Theft dropped off entirely.

Where each control actually lives

This is the part most write-ups skip. The Top 10 lists risks, and a risk is not a product feature. Four belong to the inference path, where a gateway sits. Three belong to application code. Three belong to pipelines a gateway never sees.

Risk Where the control lives What a gateway can do What it cannot do
LLM01 Prompt Injection Gateway input hook + app design Block injection and jailbreak patterns; scan tool arguments Solve it - detection is probabilistic
LLM02 Sensitive Information Disclosure Gateway, both hooks + data layer Redact PII and secrets in prompts, responses, tool results Stop a leak caused by the wrong document being indexed
LLM03 Supply Chain Procurement, build pipeline, SBOM Constrain which models and MCP servers are reachable, and by whom Verify provenance, scan a fine-tune, audit dependencies
LLM04 Data and Model Poisoning Training and fine-tuning pipeline Nothing meaningful - it happens before inference Detect a backdoor baked into weights
LLM05 Improper Output Handling The consuming application Scan output for unsafe code patterns and secrets Escape HTML or parameterise your SQL
LLM06 Excessive Agency Gateway / MCP layer + agent design Gate every tool call: allowlist, scope per subject, require approval, block destructive arguments Decide which capabilities the agent should have
LLM07 System Prompt Leakage Application architecture Detect exfiltration attempts on input; strip secrets from output Fix a design that puts credentials in the system prompt
LLM08 Vector and Embedding Weaknesses RAG pipeline and vector store Little - retrieval happens inside your application Enforce isolation in an index it does not own
LLM09 Misinformation Evaluation, product design, UX Run hallucination and faithfulness checks on output Make the model correct
LLM10 Unbounded Consumption Gateway Rate limit and budget cap by user, team, virtual account, model, or metadata Control spend on traffic that bypasses it

Four squarely in scope, three partials, three needing an owner elsewhere. If your AI security framework has a gateway row for LLM04 and LLM08, that row is decorative.

A gateway covers LLM01, LLM02, LLM06, and LLM10 well because all four are request-path problems: they happen the moment a prompt goes out or a tool fires, which is the only moment a gateway sees. The rest were decided weeks earlier, in a training run or an indexing job.

Where teams get this wrong

Treating the list as a compliance checklist. OWASP publishes a risk taxonomy with mitigation guidance, not a certification. There is no OWASP LLM Top 10 audit and no body that issues a pass. A matrix claiming all ten are “covered” by one tool is written to survive a meeting, not an attack.

Putting output validation in the wrong place. LLM05 is about what your application does with model output. A gateway can flag that a response contains os.system or an unescaped script tag. It cannot stop your service feeding that string into a shell. The control belongs where output is consumed; the gateway check is defence in depth.

Assuming injection detection is prevention. Detection is a classifier, classifiers have false negatives, and attackers iterate against them. The durable mitigation for LLM01 is to assume injection occasionally succeeds and make that survivable - which is really an LLM06 problem. Narrow the tool surface and a successful injection reaches a model with nothing dangerous to call.

Ignoring LLM10 as a billing concern. An agent stuck in a loop is a denial-of-service against your own budget, and high-volume querying is how model extraction works. It is the easiest entry to close, and the most commonly left open.

Want to see which of these you can close today?
Attach a guardrail group to a single model and watch it fire in Request Traces.

How this works in TrueFoundry

TrueFoundry’s AI Gateway implements these controls as guardrails on hooks in the request path. There are four, and which risks you can address depends on which hook you are on.

For LLM requests: input, before the prompt reaches the model, and output, after it responds.

TrueFoundry AI Gateway LLM request flow with input guardrails before the model call and output guardrails after

For MCP tool calls: mcp_pre_tool, before the tool executes, and mcp_post_tool, after it returns.

MCP tool invocation flow with pre-tool guardrails before execution and post-tool guardrails before the result returns

Those MCP hooks make the owasp mcp question tractable. Guardrails run on every tool call separately - five tools in a row means five sets of checks. A pre-tool failure means the tool never runs; a post-tool failure withholds the result.

Each guardrail has an operation mode - validate inspects and can block, mutate also rewrites - and an enforcement strategy covering violations and guardrail errors:

Try now.

One gateway for all your models, MCP servers, and agents.
No credit card needed.

INSCRIVEZ-VOUS
Table des matières

Gouvernez, déployez et suivez l'IA dans votre propre infrastructure

Réservez un séjour de 30 minutes avec notre Expert en IA

Réservez une démo

Le moyen le plus rapide de créer, de gérer et de faire évoluer votre IA

Démo du livre
Summarize with
ChatGPT logo by OpenAI
Perplexity AI logo
Blurry red snowflake on white background, symmetrical frosty design with soft edges and abstract shape.

Découvrez-en plus

Aucun article n'a été trouvé.
LLM capabilities comparison
September 22, 2026
|
5 min de lecture

Un moyen pratique de comparer les capacités du LLM

Aucun article n'a été trouvé.
Envoy proxy alternatives
September 22, 2026
|
5 min de lecture

Les 5 meilleures alternatives au proxy Envoy

Aucun article n'a été trouvé.
Generative AI gateway
September 22, 2026
|
5 min de lecture

Qu'est-ce que Generative AI Gateway ?

Aucun article n'a été trouvé.
AI guardrails in enterprise
September 22, 2026
|
5 min de lecture

Les garde-fous de l'IA en entreprise : garantir une innovation sûre

Outils LLM
Aucun article n'a été trouvé.

Blogs récents

Black left pointing arrow symbol on white background, directional indicator.
Black left pointing arrow symbol on white background, directional indicator.

Questions fréquemment posées

What is the OWASP LLM Top 10?

A consensus list of the ten most critical security risks in LLM applications, from the OWASP GenAI Security Project. The current version is the 2025 list: prompt injection, sensitive information disclosure, supply chain, data and model poisoning, improper output handling, excessive agency, system prompt leakage, vector and embedding weaknesses, misinformation, and unbounded consumption. It is guidance, not a certification - there is no audit to pass.

Can an AI gateway cover the whole OWASP LLM Top 10?

No. A gateway sits in the request path, so it addresses request-path risks well: prompt injection, sensitive information disclosure, excessive agency, and unbounded consumption. It partly helps with improper output handling, misinformation, and supply chain. Poisoning and vector weaknesses happen in training and retrieval pipelines a gateway never touches.

How does the OWASP LLM Top 10 apply to MCP?

Mostly through LLM06 Excessive Agency and LLM01 Prompt Injection. An MCP tool call is where a compromised prompt turns into a real action, so the controls that matter sit on the tool path: a mcp_pre_tool hook validating arguments before execution, a mcp_post_tool hook cleaning results before the model sees them, tool-level allowlisting, and approval on destructive calls. TrueFoundry runs guardrails on every tool call separately, not once per conversation.

Can I deploy TrueFoundry in my own VPC or on-prem?

Yes. TrueFoundry runs in your VPC, on-prem, air-gapped, or hybrid, so prompts and responses never leave your domain even as you route across many providers.

Does TrueFoundry support MCP and AI agents generally?

Yes. It includes an MCP Gateway, an Agent Gateway, and an MCP & Agents Registry with tool-level access control. Agents on LangGraph, CrewAI, AutoGen, or a custom framework can all be governed centrally.

S'intègre-t-elle à ma pile d'observabilité existante ?

Oui. La passerelle est compatible OpenTelemetry et s'intègre à Grafana, Datadog, Prometheus, ou à votre pile technologique préférée. Elle trace chaque requête, du prompt à l'exécution de l'outil et du modèle, vous offrant ainsi une journalisation unifiée sans avoir à remplacer ce que vous utilisez déjà.

Faites un rapide tour d'horizon des produits
Commencer la visite guidée du produit
Visite guidée du produit