Discrepancy Between OWASP LLM Risk Rankings and Real-World Incidents
August 21, 2026
An analysis of 14,353 labeled LLM security incidents reveals a weak agreement (Cohen's kappa ≈ 0.20) between the OWASP Top 10 expert rankings and empirical incident data. The study uses a Bayesian measurement-error model to derive a 2026 candidate list that weights expert consensus against observed vulnerabilities.
HOW THIS AFFECTS YOU
●
builderYou can prioritize security hardening based on a blend of expert consensus and empirical incident data.
●
policyYou should note the gap between perceived and actual LLM security risks when drafting compliance frameworks.