Application failure-mode lens for large language model (LLM) systems. Mappings identify risks a requirement should address and are not proof of product efficacy or OWASP endorsement.
Scope
All-market research view
This page includes every security requirement connected to OWASP Top 10 for LLM Applications. Vendor counts, alphabetical examples, and public-support findings come from the current 66-vendor research set; this is not a vendor-specific assessment.
Version2025 (v2.0)Current source
Connected requirements13security questions in this research
Security requirements18used consistently across vendors
References25identifiers, clauses, safeguards, or categories
How to use this map
Framework connections help structure your evaluation
Each connection shows how a security requirement relates to this framework. Public vendor claims are shown separately, and deployed effectiveness still requires confirmation or testing.
Contributes
8
Closely aligned
5
Requirement connections
From framework reference to testable evidence
Each row shows how the security requirement relates to the framework, the current public-support findings, and what to verify.
ContributesSpecific reference
AI usage inventory
Maintain an inventory of AI tools, services, models, agents, software as a service (SaaS) AI capabilities, data flows, and provider relationships.
Framework references
LLM03:2025
Lifecycle
Govern · Identify · Monitor
Vendors with public support
66 of 66 vendors reviewed
Foundational security requirementUnapproved AI use discovery
Discover and monitor workforce AI tools, accounts, prompts, domains, models, users, and usage outside approved controls.
Strong public support
44
Limited public support
7
No supporting claim found
15
Research incomplete
0
Foundational security requirementAI-feature discovery in business applications
Inventory software as a service (SaaS) applications that embed AI features, expose enterprise data to AI capabilities, or create AI-driven data movement.
Strong public support
20
Limited public support
11
No supporting claim found
35
Research incomplete
0
Foundational security requirementApproved AI usage monitoring
Monitor approved AI workspaces, tenants, gateways, and model platforms such as ChatGPT Enterprise, Claude Enterprise, Gemini, Microsoft Copilot, Vertex AI, Elvex, or internal AI gateways.
Strong public support
37
Limited public support
23
No supporting claim found
6
Research incomplete
0
ContributesSpecific reference
AI usage monitoring
Monitor AI usage, user activity, prompts, responses, provider calls, runtime actions, and anomalous behavior.
Framework references
LLM10:2025
Lifecycle
Monitor · Detect · Operate
Vendors with public support
66 of 66 vendors reviewed
Foundational security requirementUnapproved AI use discovery
Discover and monitor workforce AI tools, accounts, prompts, domains, models, users, and usage outside approved controls.
Strong public support
44
Limited public support
7
No supporting claim found
15
Research incomplete
0
Foundational security requirementApproved AI usage monitoring
Monitor approved AI workspaces, tenants, gateways, and model platforms such as ChatGPT Enterprise, Claude Enterprise, Gemini, Microsoft Copilot, Vertex AI, Elvex, or internal AI gateways.
Observe and govern agent plans, memory, tool calls, delegated tasks, autonomy, runtime decisions, and outcomes.
Strong public support
49
Limited public support
13
No supporting claim found
4
Research incomplete
0
ContributesSpecific reference
unapproved AI control
Enforce policy against unapproved AI tools or unsafe AI interactions through blocking, coaching, allowlists, or runtime controls.
Framework references
LLM01:2025 · LLM06:2025
Lifecycle
Protect · Deploy · Operate
Vendors with public support
64 of 66 vendors reviewed
Foundational security requirementControls for unapproved AI use
Block, coach, redirect, or contain non-approved AI use and policy-violating AI interactions.
Strong public support
37
Limited public support
14
No supporting claim found
15
Research incomplete
0
Additional security requirementBrowser and business-application controls
Apply session-level controls in browser and software as a service (SaaS) workflows, including uploads, downloads, copy/paste, sharing, and identity-aware access decisions.
Strong public support
19
Limited public support
10
No supporting claim found
37
Research incomplete
0
Additional security requirementGenerative AI application security
Protect enterprise-built large language model (LLM) applications, retrieval-augmented generation (RAG) systems, prompts, application programming interfaces (APIs), model calls, tools, and production runtime behavior.
Strong public support
39
Limited public support
17
No supporting claim found
10
Research incomplete
0
Closely alignedSpecific reference
AI data protection
Prevent sensitive data exposure through prompts, responses, files, retrieval, memory, embeddings, or AI-connected workflows.
Framework references
LLM02:2025 · LLM07:2025 · LLM08:2025
Lifecycle
Protect · Operate · Monitor
Vendors with public support
65 of 66 vendors reviewed
Foundational security requirementSensitive-data protection for generative AI
Detect, classify, redact, or block sensitive data in prompts, responses, files, retrieval, memory, and AI-connected workflows.
Strong public support
43
Limited public support
15
No supporting claim found
8
Research incomplete
0
Additional security requirementGenerative AI application security
Protect enterprise-built large language model (LLM) applications, retrieval-augmented generation (RAG) systems, prompts, application programming interfaces (APIs), model calls, tools, and production runtime behavior.
Strong public support
39
Limited public support
17
No supporting claim found
10
Research incomplete
0
Foundational security requirementApproved AI usage monitoring
Monitor approved AI workspaces, tenants, gateways, and model platforms such as ChatGPT Enterprise, Claude Enterprise, Gemini, Microsoft Copilot, Vertex AI, Elvex, or internal AI gateways.
Strong public support
37
Limited public support
23
No supporting claim found
6
Research incomplete
0
Closely alignedSpecific reference
generative AI application security
Secure large language model (LLM) applications, retrieval-augmented generation (RAG) systems, prompts, tool calls, application programming interfaces (APIs), model interactions, and runtime behavior.
Additional security requirementGenerative AI application security
Protect enterprise-built large language model (LLM) applications, retrieval-augmented generation (RAG) systems, prompts, application programming interfaces (APIs), model calls, tools, and production runtime behavior.
Strong public support
39
Limited public support
17
No supporting claim found
10
Research incomplete
0
Foundational security requirementSensitive-data protection for generative AI
Detect, classify, redact, or block sensitive data in prompts, responses, files, retrieval, memory, and AI-connected workflows.
Strong public support
43
Limited public support
15
No supporting claim found
8
Research incomplete
0
Foundational security requirementControls for unapproved AI use
Block, coach, redirect, or contain non-approved AI use and policy-violating AI interactions.
Strong public support
37
Limited public support
14
No supporting claim found
15
Research incomplete
0
Foundational security requirementAI gateway, tool-connection, and runtime controls
Mediate model, agent, tool, application programming interface (API), connector, and Model Context Protocol (MCP) traffic through an enforcement point that applies identity-aware policy, content controls, routing, rate limits, and auditable allow or deny decisions.
Strong public support
42
Limited public support
19
No supporting claim found
5
Research incomplete
0
ContributesSpecific reference
AI governance, risk, and compliance operations
Maintain accountable AI inventory, policy, risk assessments, approvals, exceptions, regulatory mappings, third-party oversight, and audit evidence across the AI lifecycle.
Framework references
LLM03:2025
Lifecycle
Govern · Identify · Assess · Approve · Monitor
Vendors with public support
66 of 66 vendors reviewed
Foundational security requirementAI governance, risk, and compliance
Inventory AI systems and owners, translate policy and regulatory obligations into governed workflows, assess risk, manage approvals and exceptions, and retain audit evidence across the AI lifecycle.
Strong public support
36
Limited public support
20
No supporting claim found
10
Research incomplete
0
Foundational security requirementApproved AI usage monitoring
Monitor approved AI workspaces, tenants, gateways, and model platforms such as ChatGPT Enterprise, Claude Enterprise, Gemini, Microsoft Copilot, Vertex AI, Elvex, or internal AI gateways.
Strong public support
37
Limited public support
23
No supporting claim found
6
Research incomplete
0
Foundational security requirementAI-feature discovery in business applications
Inventory software as a service (SaaS) applications that embed AI features, expose enterprise data to AI capabilities, or create AI-driven data movement.
Strong public support
20
Limited public support
11
No supporting claim found
35
Research incomplete
0
Closely alignedSpecific reference
AI assurance, red teaming, and supply-chain security
Test models, applications, retrieval-augmented generation (RAG) systems, agents, coding workflows, and AI artifacts before release and continuously thereafter, with reproducible findings and remediation gates.
Framework references
LLM01:2025 · LLM03:2025 · LLM05:2025
Lifecycle
Develop · Test · Release · Monitor
Vendors with public support
57 of 66 vendors reviewed
Foundational security requirementAI assurance and adversarial testing
Test models, applications, retrieval-augmented generation (RAG) systems, and agents before release and continuously thereafter using adversarial probes, evaluation suites, attack simulation, and security release gates.
Strong public support
24
Limited public support
3
No supporting claim found
39
Research incomplete
0
Foundational security requirementAI model and supply-chain security
Discover, inventory, scan, validate, and monitor models, datasets, model artifacts, registries, dependencies, and AI development assets for tampering, unsafe serialization, provenance gaps, or malicious content.
Strong public support
13
Limited public support
28
No supporting claim found
25
Research incomplete
0
Additional security requirementAI coding-agent and workstation security
Discover and govern AI coding agents, integrated development environment (IDE) assistants, command-line agents, skills, hooks, extensions, Model Context Protocol (MCP) tools, filesystem access, commands, network activity, secrets, and software-supply-chain actions on developer workstations and build environments.
Strong public support
14
Limited public support
27
No supporting claim found
25
Research incomplete
0
Closely alignedSpecific reference
Third-party and software as a service (SaaS) AI risk
Understand and monitor AI risk introduced by external software as a service (SaaS), AI providers, embedded AI features, and supplier services.
Framework references
LLM03:2025 · LLM04:2025
Lifecycle
Govern · Identify · Detect
Vendors with public support
51 of 66 vendors reviewed
Foundational security requirementAI-feature discovery in business applications
Inventory software as a service (SaaS) applications that embed AI features, expose enterprise data to AI capabilities, or create AI-driven data movement.
Strong public support
20
Limited public support
11
No supporting claim found
35
Research incomplete
0
Foundational security requirementUnapproved AI use discovery
Discover and monitor workforce AI tools, accounts, prompts, domains, models, users, and usage outside approved controls.
Strong public support
44
Limited public support
7
No supporting claim found
15
Research incomplete
0
Platform contextApproved AI platform context
Where a vendor's public claims appear to complement, overlap with, or sit outside native controls in approved enterprise AI deployments.
Strong public support
0
Limited public support
0
No supporting claim found
0
Research incomplete
66
ContributesSpecific reference
Agentic telemetry and behavior monitoring
Observe agent steps, plans, goals, memory, delegation, tool use, and anomalies during runtime.
Observe and govern agent plans, memory, tool calls, delegated tasks, autonomy, runtime decisions, and outcomes.
Strong public support
49
Limited public support
13
No supporting claim found
4
Research incomplete
0
Foundational security requirementAgent-to-agent communication security
Authorize, log, and control agent-to-agent, agent-to-tool, Model Context Protocol (MCP), connector, and tool-chain handoffs.
Strong public support
12
Limited public support
34
No supporting claim found
20
Research incomplete
0
Foundational security requirementNon-human identity and service-account security
Inventory, least privilege, credential hygiene, monitoring, and lifecycle management for non-human identities, workloads, service accounts, application programming interface (API) keys, and machine credentials.
Strong public support
14
Limited public support
19
No supporting claim found
33
Research incomplete
0
ContributesSpecific reference
Agent-to-agent and tool communication security
Secure trust, authorization, message flows, tool access, and communication between agents, tools, application programming interfaces (APIs), and external services.
Framework references
LLM06:2025
Lifecycle
Identify · Protect · Deploy · Monitor
Vendors with public support
66 of 66 vendors reviewed
Foundational security requirementAgent-to-agent communication security
Authorize, log, and control agent-to-agent, agent-to-tool, Model Context Protocol (MCP), connector, and tool-chain handoffs.
Observe and govern agent plans, memory, tool calls, delegated tasks, autonomy, runtime decisions, and outcomes.
Strong public support
49
Limited public support
13
No supporting claim found
4
Research incomplete
0
Additional security requirementGenerative AI application security
Protect enterprise-built large language model (LLM) applications, retrieval-augmented generation (RAG) systems, prompts, application programming interfaces (APIs), model calls, tools, and production runtime behavior.
Strong public support
39
Limited public support
17
No supporting claim found
10
Research incomplete
0
Foundational security requirementAI gateway, tool-connection, and runtime controls
Mediate model, agent, tool, application programming interface (API), connector, and Model Context Protocol (MCP) traffic through an enforcement point that applies identity-aware policy, content controls, routing, rate limits, and auditable allow or deny decisions.
Strong public support
42
Limited public support
19
No supporting claim found
5
Research incomplete
0
ContributesSpecific reference
non-human identity (NHI) and AI-agent identity governance
Manage identities, credentials, privileges, secrets, service accounts, and lifecycle for AI agents and other non-human identities.
Framework references
LLM06:2025
Lifecycle
Govern · Protect · Deploy · Operate
Vendors with public support
60 of 66 vendors reviewed
Foundational security requirementNon-human identity and service-account security
Inventory, least privilege, credential hygiene, monitoring, and lifecycle management for non-human identities, workloads, service accounts, application programming interface (API) keys, and machine credentials.
Strong public support
14
Limited public support
19
No supporting claim found
33
Research incomplete
0
Foundational security requirementAI agent identity and permissions
Register AI agents as accountable identities, bind them to owners and delegating users, authorize task- and tool-level access, issue short-lived credentials, review access, and revoke or suspend agent authority.
Strong public support
15
Limited public support
39
No supporting claim found
12
Research incomplete
0
Foundational security requirementAgent-to-agent communication security
Authorize, log, and control agent-to-agent, agent-to-tool, Model Context Protocol (MCP), connector, and tool-chain handoffs.
Strong public support
12
Limited public support
34
No supporting claim found
20
Research incomplete
0
Foundational security requirementAI-feature discovery in business applications
Inventory software as a service (SaaS) applications that embed AI features, expose enterprise data to AI capabilities, or create AI-driven data movement.
Strong public support
20
Limited public support
11
No supporting claim found
35
Research incomplete
0
Closely alignedSpecific reference
AI FinOps and cost accountability
Attribute AI usage and spend to accountable owners, workflows, agents, models, and business units while enforcing budget, rate-limit, and routing controls.
Framework references
LLM06:2025 · LLM10:2025
Lifecycle
Govern · Operate · Optimize
Vendors with public support
66 of 66 vendors reviewed
Additional security requirementAI cost and usage controls
Visibility, attribution, budgeting, rate limiting, anomaly detection, and optimization for AI usage and spend across models, agents, workflows, and owners.
Strong public support
5
Limited public support
9
No supporting claim found
46
Research incomplete
6
Foundational security requirementApproved AI usage monitoring
Monitor approved AI workspaces, tenants, gateways, and model platforms such as ChatGPT Enterprise, Claude Enterprise, Gemini, Microsoft Copilot, Vertex AI, Elvex, or internal AI gateways.
Observe and govern agent plans, memory, tool calls, delegated tasks, autonomy, runtime decisions, and outcomes.
Strong public support
49
Limited public support
13
No supporting claim found
4
Research incomplete
0
Foundational security requirementNon-human identity and service-account security
Inventory, least privilege, credential hygiene, monitoring, and lifecycle management for non-human identities, workloads, service accounts, application programming interface (API) keys, and machine credentials.
Strong public support
14
Limited public support
19
No supporting claim found
33
Research incomplete
0
ContributesSpecific reference
Enterprise AI platform context
Show whether vendor claims complement, overlap with, or sit outside native controls in approved enterprise AI platforms such as ChatGPT Enterprise, Claude Enterprise, Gemini Enterprise, Gemini for Google Cloud, Microsoft Copilot, Vertex AI, or an internal AI gateway.
Framework references
LLM03:2025
Lifecycle
Architecture context
Vendors with public support
0 of 66 vendors reviewed
Platform contextApproved AI platform context
Where a vendor's public claims appear to complement, overlap with, or sit outside native controls in approved enterprise AI deployments.
Strong public support
0
Limited public support
0
No supporting claim found
0
Research incomplete
66
This page organizes research. Audit conclusions, certification assessments, control implementation statements, and vendor endorsements require separate evidence.