← AI security in plain English

LLM10

OWASP Top 10 for LLMs / Unbounded Consumption

An LLM is allowed to run without sensible limits, so attackers can flood it with heavy requests that drain computing resources, run up costs, or knock the service offline.

Think of it likeA guest who leaves every faucet and the garden hose running all day, spiking your water bill until the tank runs dry.

In plain English

Without caps on how much work an AI will do, attackers can overload it with expensive requests, racking up huge bills or crashing the service for everyone.