As artificial intelligence (AI) tools continue to proliferate among nearly all sectors and organizations, risks associated with their use will also continue to multiply. OWASP – the Open Worldwide Application Security Project – recently updated its list of the top dangers facing large language models (LLMs). The “OWASP Top 10 for LLM Applications 2025” explores the latest risks, vulnerabilities, and mitigations for developing and securing generative AI and LLMs across the development, deployment, and management lifecycle. This updated resource comes as DHS recently released its Roles and Responsibilities Framework for AI in Critical Infrastructure.
OWASP dives into each risk, providing extensive discussion, mitigations, and security recommendations. If your utility is using or considering using AI , WaterISAC highly encourages members to utilize the OWASP top 10 as the primary risks to plan mitigations for. The Top 10 includes:
- Prompt injection
- Sensitive information disclosure
- Supply chain
- Data and model poisoning
- Improper output handling
- Excessive agency
- System prompt leakage
- Vector and embedding weaknesses
- Misinformation
- Unbounded consumption
For more information, visit OWASP.