Definition
A ranked list of the ten most critical security risks in applications built on large language models, compiled by security practitioners from real-world incidents and expert votes. It is the closest thing the industry has to a common checklist for what can go wrong with AI applications, similar to how the classic OWASP Top 10 became a baseline for web-app security.
Why it matters
Boards should expect vendors, auditors, and internal security teams to reference this list when assessing AI risk; it is quickly becoming the shared vocabulary regulators and insurers use to judge whether an organization's AI security program is adequate.