All 52 threats in full: description, impact, example, mitigations and verified sources.
To the catalogueTwo threats and the references they share
Choose two threats or one of the suggested pairs with a large overlap. The middle column shows the references both point to; the outer ones show what applies to only one of them. The mitigations of both sides are listed below.
Who it is for: For anyone drafting policies, training material or audit plans
Threat comparison
Only Backdoor ML Model4
Model and Training Data Manipulation · Development
BIML BIML78 model:2BSI R20NIST AI RMF NISTAML.021NIST AI RMF NISTAML.026
Shared by both11
the same reference in the same framework
BIML BIML-LLM model:4BSI R19EU AI Act Article 53(1)(a)EU AI Act Article 55(1)(a)EU AI Act Article 9(1), 9(2)(a), 9(2)(d)MITRE ATLAS AML.T0018NIST AI RMF MEASURE 2.7NIST AI RMF NISTAML.023NIST AI RMF NISTAML.051NIST AI RMF Section 2.9OWASP LLM Top 10 LLM04:2025
Only Sleepy Agent (Time/Event-Triggered Hidden Instructions)1
Model and Training Data Manipulation · Development
MITRE ATLAS AML.T0020
Backdoor ML Model 4 mitigations
The model contains hidden behavior, a backdoor. It works correctly on normal inputs; only a secret trigger pattern in the input flips the output to whatever result the attacker has chosen.
-
Model scanning for backdoors
Reason for the classification
Primarily technical: Software or analytical tools systematically produce and evaluate measurements, deviations, or attack indicators.
-
Neural cleanse techniques
Reason for the classification
Primarily technical: Software or analytical tools systematically produce and evaluate measurements, deviations, or attack indicators.
-
Activation clustering analysis
Reason for the classification
Primarily technical: Software or analytical tools systematically produce and evaluate measurements, deviations, or attack indicators.
-
Train from trusted base models only
Reason for the classification
Primarily organizational and process-based: Defined selection, operating, or lifecycle procedures make the control binding and repeatable; complemented by technical implementation.
Sleepy Agent (Time/Event-Triggered Hidden Instructions) 6 mitigations
Malicious logic lies dormant inside the model and only activates later: on a set date, at a specific event, or in a particular environment. Until then, the system passes every test and review without raising suspicion.
-
Behavioral analysis under diverse conditions
Reason for the classification
Primarily technical: Software or analytical tools systematically produce and evaluate measurements, deviations, or attack indicators.
-
Time-shifted testing
Reason for the classification
Primarily technical: Software or analytical tools systematically produce and evaluate measurements, deviations, or attack indicators.
-
Adversarial evaluation across contexts
Reason for the classification
Primarily technical: Software or analytical tools systematically produce and evaluate measurements, deviations, or attack indicators.
-
Runtime behavior monitoring
Reason for the classification
Primarily technical: Software or analytical tools systematically produce and evaluate measurements, deviations, or attack indicators; complemented by binding workflows.
-
Model interpretability tools
Reason for the classification
Primarily technical: Software or analytical tools systematically produce and evaluate measurements, deviations, or attack indicators.
-
Supply chain integrity verification
Reason for the classification
Primarily technical: Software or analytical tools systematically produce and evaluate measurements, deviations, or attack indicators; complemented by binding workflows.
Threat pathwayThe threat pathway shows how one of these threats unfolds in detail.
A shared reference means that both threats point to the same place in the same framework. It does not mean that one mitigation covers both.
Versatile AI Risk Assessment is an aid for structuring AI risks and making them transparent. It does not replace legal or professional advice and makes no binding decisions.
The same data, a different question
What defines a threat, when it arises and how it differs from another.
-
Threat pathway
How does harm arise?
For anyone working through a threat in depth for the first time
-
Lifecycle
When does which risk arise?
For governance, procurement and programme management
- System context Which threats affect my system?
- Architecture change What does a rebuild trigger?
- Effect matrix How and where do mitigations take effect?
- Ownership Who has to act?
- Framework mappings Where is this anchored professionally and legally?
- Coverage gaps What does my framework not reach?
- Evidence base What is this based on?
From the analysis to the assessment
Four short sections along the EU AI Act for a first, non‑binding orientation of your system.
To the quick checkThe full assessment with system context, threat selection and evidence tracking, free of charge in the browser.
To the live demo