Abstract
This chapter provides a comprehensive overview of security considerations, vulnerabilities, and controls at the application layer for GenAI systems. Analysis of the OWASP Top 10 for LLM applications gives the initial context of security concerns of GenAI Applications. Leading application design paradigms including RAG, ReAct, and agent-based systems are explored, along with their security implications. Major cloud-based AI services and associated security features are discussed. The Cloud Security Alliance’s Cloud Control Matrix is leveraged to evaluate application security controls relevant to GenAI. Examples grounded in banking connect security controls to real-world scenarios. Through multifaceted coverage of risks, design patterns, services, and control frameworks, the chapter equips readers with actionable insights on securing diverse GenAI applications by integrating security across the full application life cycle.