Versatile AI Risk Assessment

The catalogue seen from the perspective of a concrete system type

Choose the system type and the architectural characteristics that apply. The grid shows, for each of the 52 threats, whether it is always to consider for this profile, needs review in the individual case, or remains atypical for this system type. A characteristic you set can put an atypical threat back up for review.

Who it is for: For architecture, product ownership and anyone assessing a concrete system

System context

1. System type
2. Architectural characteristics

Systems with tool use, memory, planning steps, or autonomous execution need a stronger focus on agency, tool safety, session context, and human oversight.

37 Always consider Regularly relevant for this system type. The assessment should address this threat explicitly.
15 To review Relevant depending on architecture and deployment. The person carrying out the assessment decides case by case.
0 Atypical Atypical for this system type. This does not rule the threat out; matching architectural characteristics put it back up for review.

All 52 threats, bundled by topic group.

  1. Supply Chain and Provenance2/3

  2. Model and Training Data Manipulation1/4

  3. Prompt Attacks and Guardrail Evasion4/5

  4. Attacks on the Running Model and Service5/7

  5. Privacy and Data Leakage4/4

  6. Application and Integration Security7/7

  7. Harmful Content2/9

  8. Malicious Use for Attacks, Fraud and Disinformation3/4

  9. Agentic and Autonomous AI5/5

  10. Reliability and Responsible Use4/4

Review questions for this system type
  • Which tools can the agent invoke and with which privileges?
  • Which actions require explicit human approval?
  • Can external or stored context influence future agent decisions?
The file shows the current state including any filters and carries the note, catalogue version and source.

The assignment is a working basis for the assessment, not a clearance. “Atypical for this profile” does not mean “ruled out”: the professional decision still rests with the person carrying out the assessment.

Versatile AI Risk Assessment is an aid for structuring AI risks and making them transparent. It does not replace legal or professional advice and makes no binding decisions.

Placing your own system

The same data, a different question

Which part of the catalogue applies to a concrete system boundary and what changes on a rebuild.

  1. Preview of the analysis: Architecture change Architecture change What does a rebuild trigger? For architecture, product ownership and anyone facing a change to the system boundary
Understanding threats
Planning mitigations
Checking frameworks and evidence

Overview of all ten analyses

Related
Threat catalogue

All 52 threats in full: description, impact, example, mitigations and verified sources.

To the catalogue
EU AI Act quick check

Four short sections along the EU AI Act for a first, non‑binding orientation of your system.

To the quick check
Assess it yourself

The full assessment with system context, threat selection and evidence tracking, free of charge in the browser.

To the live demo