Section 04
4The Regulatory and Threat Landscape
The financial and regulatory consequences of ungoverned AI are substantial. Under the EU AI Act, penalties scale with global turnover, so an undeclared tool that crosses into a prohibited or high-risk category becomes a board-level liability rather than an IT incident.
| Violation category | Description of offense | Maximum penalty |
|---|---|---|
| Prohibited practices (Art. 5) | Subliminal techniques, exploiting vulnerabilities, unauthorized biometric categorization | €35M or 7% of global turnover, whichever is higher |
| High-risk non-compliance (Art. 6–49) | No risk management, data governance or human oversight | €15M or 3% of global turnover, whichever is higher |
| Misleading information | Incorrect or misleading information to regulators | €7.5M or 1% of global turnover, whichever is higher |
Table 2. EU AI Act violation categories and maximum penalties. Source: EU AI Act regulatory framework guidelines.
The timeline has since moved. The Digital Omnibus on AI — Regulation (EU) 2026/1744, in force since 27 July 2026 — defers high-risk obligations for stand-alone Annex III systems to 2 December 2027 and for AI embedded in regulated products (Annex I) to 2 August 2028. Article 50 transparency duties still apply from 2 August 2026, and a new Article 5 prohibition on AI-generated non-consensual intimate imagery and child sexual abuse material applies from 2 December 2026. The penalty ceilings above are unchanged; the deferral buys preparation time, not an exemption.
The technical threat surface is mapped by the OWASP Top 10 for LLM Applications. Each category corresponds to an exposure pathway that shadow tools open by default — from prompt injection and sensitive-information leakage to excessive agency and ‘Denial of Wallet’ consumption attacks.

Text in this figure
Input · LLM01 · Prompt Injection · Output · LLM02 · Sensitive Information Disclosure · LLM05 · Improper Output Handling · LLM07 · System Prompt Leakage · Model · LLM03 · Supply Chain · LLM04 · Data & Model Poisoning · LLM08 · Vector & Embedding Weaknesses · Agency · LLM06 · Excessive Agency · LLM09 · Misinformation · LLM10 · Unbounded Consumption
| OWASP risk | Vulnerability description | Enterprise security impact |
|---|---|---|
| LLM01 · Prompt Injection | Adversarial inputs (direct or indirect) that overwrite system prompts | Safety bypasses, unauthorized commands, malicious code in the developer environment |
| LLM02 · Sensitive Information Disclosure | Leakage of proprietary algorithms, PII or architecture via output | Exposes corporate secrets, voids IP and triggers regulatory penalties |
| LLM03 · Supply Chain | Compromised third-party models, datasets or hallucinated plugins | Silent backdoors, biased logic and large-scale upstream breaches |
| LLM04 · Data and Model Poisoning | Deliberate manipulation of training data, fine-tuning or embeddings | Selective degradation, harmful output or hidden “sleeper agent” activation |
| LLM05 · Improper Output Handling | Outputs passed downstream without validation, sanitization or encoding | Classic web exploits: XSS, SSRF and remote code execution |
Table 3. OWASP Top 10 for LLM Applications: vulnerability and enterprise impact (LLM01–LLM05).
| OWASP risk | Vulnerability description | Enterprise security impact |
|---|---|---|
| LLM06 · Excessive Agency | Broad permissions to call APIs or databases with no human in the loop | Rogue agents delete production data or alter access control |
| LLM07 · System Prompt Leakage | Disclosure of the instructions that bound the model’s behaviour | Adversaries reverse-engineer defences, steal prompt IP, craft bypasses |
| LLM08 · Vector and Embedding Weaknesses | Flaws in generation, storage or retrieval within RAG | Poisoned vector stores surface malicious context and instructions |
| LLM09 · Misinformation | Model generates confident but false output that users accept without verification | Insecure code in production, defamatory content, legal liability |
| LLM10 · Unbounded Consumption | Overloading costly inference to overwhelm services (Denial of Wallet) | Billing spikes, exhausted cloud capacity, severe latency |
Table 3 (cont.). LLM06–LLM10. Source: OWASP Top 10 for LLM Applications, 2025 edition (current).
Tip: use ← → to move between sections.
