Versatile AI Risk Assessment

Who it is for Information security

Identifying and assessing AI threats

Manipulated training data, injected instructions and excessive agent permissions can put AI systems at risk. The threat catalogue helps you assess these risks for your system, select mitigations and document your reasoning.

The starting point

Familiar threat modelling still carries, but it falls short. A language model does not distinguish instruction from content: processing a document means processing the instructions inside it. An agent with tool access executes what appears plausible to it. And a model carries properties that arose during training and are no longer visible in operation.

The catalogue orders 52 threats into ten topic groups and three phases: three from the supply chain, four from development, 45 from operation. Each names its mitigations with control type, effect and implementation level, plus its references in OWASP, MITRE ATLAS, NIST and the publications of the German federal office.

A language model does not distinguish instruction from content. Processing a document means processing the instructions inside it.

Prompt injection, indirect

Assessments step by step (2)

Each step links to the relevant features and information.

  1. Select the relevant threats System type and architecture decide which of the 52 always apply.
  2. Attach mitigations 265 mitigations with control type, effect and implementation level.

Questions and answers (8)

Answers with sources and links for further review.

What is indirect prompt injection and what helps against it?

Instructions do not come from the user but from a source the system processes: a document, a web page, an image description, a tool response. The model follows them because it does not separate instruction from content. The entry in the threat catalogue lists the mitigations against this, each with its reference in the framework.

How do I secure a system that acts on its own?

Before the first real permission come five decisions: scope of rights, level of autonomy, approval requirements, logging and a kill switch. The catalogue holds five threats on autonomous agents, among them persistently poisoned memory and insecure communication between agents.

Which frameworks does the catalogue cover?

Seven, with 486 documented mappings from 21 primary sources: the EU AI Act with 51 threats, the risk framework of the US standards institute with 47, the OWASP Foundation priority list with 45, MITRE ATLAS with 44, plus the GDPR, the publications of the German federal office and the architectural analyses of the Berryville Institute. Every framework page also states which threats it does not reach.

Which threats are actually relevant for my system?

That depends on the system type and its architectural properties. The application-context analysis lets you select both and then shows which of the 52 threats always apply and which only in specific cases. A system without tool access does not need the agent group; a system without its own training needs the poisoning group only conditionally.

How do the mitigations work and where do they take effect?

265 mitigations each carry their control type, their effect and their implementation level. The effect matrix sets both against each other: which control type works on which topic group and where gaps remain. The attack path shows, for every threat, the five points where a mitigation can take effect.

Which EU AI Act obligation directly concerns security?

Art. 15 requires high-risk systems to achieve an appropriate level of accuracy, robustness and cybersecurity across the whole life cycle, expressly including resilience against attacks. For deployers Art. 26(5) is added: monitor operation and suspend it when a risk emerges.

What does the application explicitly not do for security?

It examines no running system, it reads no logs and it detects no attack. It replaces neither a management system nor a security test. It assesses a state based on what you record; whether a mitigation actually works in the specific system is not verified.

Limits of the application (4)

These tasks require additional tools or professional review.

Tasks outside the application

  • It examines no running system. It reads no logs, detects no attack and measures nothing.
  • It replaces no security test and no penetration testing.
  • It replaces no management system for information security.
  • Whether a mitigation works in the specific system is not verified. That assessment stays with you.

Suitable editions

€2,490 once

Professional Offline

For regular work across several systems: reports as PDF and workbook, machine-readable exports, extended evidence packages.

Open
free of charge

Live demo to get to know it

The complete Community Edition with example data, directly in the browser and without sign-up. For trying out the method; your own work inside a company or a public body is not covered by the Community licence.

Open

Compare the features, licence terms and prices of the Community, Professional and Enterprise editions. Compare editions

Other audiences (7)

Guidance for other responsibilities within your organisation or your clients’ organisations.

← Back to the overview