Versatile AI Risk Assessment

What a framework reaches and what remains without a reference

Choose one framework or several. The grid shows, for each of the 52 threats, whether the selection contains at least one applicable reference. Each gap names the other frameworks that do reach that threat.

Who it is for: For anyone choosing a framework or already committed to one

Coverage gaps

OWASP LLM Top 10 reaches 45 of the 52 threats. 7 remain open, of which 7 have a reference in another framework.

1framework selected
45/52threats with at least one reference
7threats without any reference
60references in the selection
  1. Supply Chain and Provenance3/3

  2. Model and Training Data Manipulation4/4

  3. Prompt Attacks and Guardrail Evasion5/5

  4. Attacks on the Running Model and Service6/7

  5. Privacy and Data Leakage4/4

  6. Application and Integration Security6/7

  7. Harmful Content6/9

  8. Malicious Use for Attacks, Fraud and Disinformation2/4

  9. Agentic and Autonomous AI5/5

  10. Reliability and Responsible Use4/4

Select a threat to see its references across all frameworks.

Without a reference in the selection · 7

Framework mappingsThe framework mappings show which references a framework carries in detail.

The file shows the current state including any filters and carries the note, catalogue version and source.

A reference means the catalogue identifies a place in the framework as applicable. Mappings indicate relevance and applicability, not evidence of compliance. A missing reference does not mean the threat is unimportant, it means this framework does not address it.

Versatile AI Risk Assessment is an aid for structuring AI risks and making them transparent. It does not replace legal or professional advice and makes no binding decisions.

Checking frameworks and evidence

The same data, a different question

Which provision applies, what it does not reach and which primary source the catalogue relies on.

  1. Preview of the analysis: Framework mappings Framework mappings Where is this anchored professionally and legally? For compliance, legal, internal audit and assurance
  2. Preview of the analysis: Evidence base Evidence base What is this based on? For assessors, internal audit and anyone judging how solid a source is
Understanding threats
Placing your own system
Planning mitigations

Overview of all ten analyses

Related
Threat catalogue

All 52 threats in full: description, impact, example, mitigations and verified sources.

To the catalogue
EU AI Act quick check

Four short sections along the EU AI Act for a first, non‑binding orientation of your system.

To the quick check
Assess it yourself

The full assessment with system context, threat selection and evidence tracking, free of charge in the browser.

To the live demo