Robot Explains Gallery
A kid-friendly visual interpretation of the 2026 OWASP Top 10 for LLM applications.
The OWASP Top 10 for LLM Applications is the security community's list of the biggest risks in AI apps. This set reimagines the 2026 list as friendly visual cards, a way to start serious conversations about AI security with students, developers, and non-specialists. For awareness and discussion, not a replacement for the official OWASP guidance.
Two lists, paired — because neither covers the other's ground:
Robot reads or writes something risky.
Robot uses tools, identity, memory, or permissions to do something risky.
When hidden instructions sneak into what the robot reads, hears, sees, or remembers.
View poster →
When the robot reveals secrets it should keep — in its answer, its reasoning, or its training data.
View poster →
When the robot is allowed to do too much, with too much power, on its own.
View poster →
When a model, tool, or package the robot loaded isn't the safe thing you thought.
View poster →
When bad training or fine-tuning data teaches the robot the wrong things — and it lasts.
View poster →
When the robot uses way too much — costing money and grinding things to a halt.
View poster →
When a fluent, confident answer is wrong — and someone acts on it.
View poster →
When the robot's backstage instructions, notes, or tool rules slip out. (Renamed from System Prompt Leakage.)
View poster →
When the robot's memory shelves mix things up, leak, or get tricked.
View poster →
When an app trusts the robot's output without checking it first.
View poster →Robot Explains is an independent educational adaptation and is not official OWASP guidance. It is based on the OWASP Top 10 for LLM Applications (2026) by the OWASP GenAI Security Project.
The OWASP material is licensed under Creative Commons Attribution-ShareAlike 4.0 (CC BY-SA 4.0), and these adapted posters are shared under the same license.