Misinformation (LLM09)
An LLM generates incorrect or misleading content that the user trusts and acts on. Hallucination is the obvious case; sycophancy and manipulated outputs are subtler. Misinformation becomes a security risk when it leads to operational decisions, legal advice, or downstream automation that depends on accuracy.
- Rank
- LLM09 of 10
- In the check
- Not cited directly by a question
What it looks like in practice
Three shapes this risk takes in real deployments.
Example 1
An LLM-based legal-research tool cites cases that do not exist.
Example 2
A chatbot's hallucinated security advice causes a customer to misconfigure access controls.
Example 3
A coding assistant suggests a non-existent npm package, which an attacker then registers maliciously.
Controls that close it
The controls the check looks for when this entry applies.
Output validation against source-of-truth where possible
User-facing confidence indicators
Disclaimer and human-review workflows for high-stakes outputs
Hallucination testing as part of release
Where the check cites it
The AI Posture Check cites OWASP LLM Top 10, including this entry, when placing you at Crawl, Walk, Run or Sprint.
The questions cite the control frameworks a regulator would expect you to hold: NIST AI RMF, ISO 42001 and the OWASP LLM Top 10. Your stage on the check is a starting point for an EU AI Act conformity review, not a substitute for one.
Other frameworks the check cites
Score yourself against this framework.
Five questions, each citing its source. You get your stage, your place on the chart and the one move that matters next.
- A few minutes for most people
- Free, from CWS
- Your stage, the chart and the next move, by email or live with an engineer