What do the assessments in the threat catalogue rest on?
On 486 documented mappings drawn from 21 primary sources across seven frameworks: the EU AI Act, the GDPR, the risk management framework of the US standards institute, the priority list of the OWASP Foundation, the MITRE ATLAS knowledge base, the publications of the German federal office for information security, and the architectural analyses of the Berryville Institute. Each of the 52 threats lists its mappings individually.
Does the same input lead to the same result?
Yes. The assessment follows fixed rules across system context, threat selection and mitigations; no language model and no random component enters the result. Anyone assessing the same system context twice receives the same result twice, including on a different machine.
How can I tell which state a result is based on?
Every output carries the catalogue version and the legal status. The catalogue currently stands at version 2026.07.17.3, the legal status is Regulation (EU) 2026/1744, in force since 27 July 2026. Both appear on the pages and in the generated documents, so that an older opinion can be placed in context later.
Which frameworks does the catalogue not cover?
The catalogue holds seven frameworks. Management system standards for artificial intelligence are not among them, nor are sector-specific rules such as those for medical devices or financial services. Every framework page states explicitly which threats that framework does not reach.
How solid is the evidence base for a single threat?
This can be read off for each threat. The evidence-base analysis shows how many references a threat carries and which frameworks they come from. Threats with a single reference are identifiable as such and should carry different weight in an opinion than those supported across several frameworks.
Can I cite an entry from the catalogue?
Yes. Every threat page and every term page carries a suggested citation at the end, with title, work, version and address. The addresses of the entries are permanent and do not change, so that a reference from an opinion still holds later.
What does the application explicitly not do for an expert opinion?
It does not judge the individual case and replaces no expert opinion. Nor does it judge whether a measure is appropriate in a specific case. It is certified against no standard and carries no management system standard for artificial intelligence. And it says nothing about whether a result will hold up in court; that is for the court to decide.