All 52 threats in full: description, impact, example, mitigations and verified sources.
To the catalogueWhat a framework reaches and what remains without a reference
Choose one framework or several. The grid shows, for each of the 52 threats, whether the selection contains at least one applicable reference. Each gap names the other frameworks that do reach that threat.
Who it is for: For anyone choosing a framework or already committed to one
Coverage gaps
-
Supply Chain and Provenance3/3
-
Model and Training Data Manipulation4/4
-
Prompt Attacks and Guardrail Evasion5/5
-
Attacks on the Running Model and Service6/7
-
Privacy and Data Leakage4/4
-
Application and Integration Security6/7
-
Harmful Content6/9
-
Malicious Use for Attacks, Fraud and Disinformation2/4
-
Agentic and Autonomous AI5/5
-
Reliability and Responsible Use4/4
Select a threat to see its references across all frameworks.
Without a reference in the selection · 7
- Application Vulnerabilitiesreached by EU AI Act, NIST AI RMF, MITRE ATLAS, BIML
- Application Denial of Servicereached by EU AI Act, MITRE ATLAS, BIML
- Profanityreached by NIST AI RMF, BSI
- Harassmentreached by EU AI Act, NIST AI RMF, MITRE ATLAS, BSI
- Unethical Actionsreached by EU AI Act, NIST AI RMF, MITRE ATLAS
- Social Engineeringreached by EU AI Act, NIST AI RMF, MITRE ATLAS, BSI
- Fraudreached by EU AI Act, NIST AI RMF, MITRE ATLAS, BSI
Framework mappingsThe framework mappings show which references a framework carries in detail.
A reference means the catalogue identifies a place in the framework as applicable. Mappings indicate relevance and applicability, not evidence of compliance. A missing reference does not mean the threat is unimportant, it means this framework does not address it.
Versatile AI Risk Assessment is an aid for structuring AI risks and making them transparent. It does not replace legal or professional advice and makes no binding decisions.
The same data, a different question
Which provision applies, what it does not reach and which primary source the catalogue relies on.
-
Framework mappings
Where is this anchored professionally and legally?
For compliance, legal, internal audit and assurance
-
Evidence base
What is this based on?
For assessors, internal audit and anyone judging how solid a source is
- Threat pathway How does harm arise?
- Lifecycle When does which risk arise?
- Threat comparison Where does the line between two run?
- System context Which threats affect my system?
- Architecture change What does a rebuild trigger?
- Effect matrix How and where do mitigations take effect?
- Ownership Who has to act?
From the analysis to the assessment
Four short sections along the EU AI Act for a first, non‑binding orientation of your system.
To the quick checkThe full assessment with system context, threat selection and evidence tracking, free of charge in the browser.
To the live demo