All 52 threats in full: description, impact, example, mitigations and verified sources.
To the catalogueThe primary sources behind the verified relations
The catalogue backs every relation with a locator in a primary document. The bars show how many references fall to each source entry, grouped by publisher. Selecting an entry shows its version, licence, link and the threats that refer to it.
Who it is for: For assessors, internal audit and anyone judging how solid a source is
Evidence base
European Union (EUR-Lex) 119 references
National Institute of Standards and Technology (NIST) 119 references
Berryville Institute of Machine Learning (BIML) 67 references
Bundesamt für Sicherheit in der Informationstechnik (BSI) 61 references
OWASP Foundation 60 references
MITRE 57 references
European Data Protection Board (EDPB) 3 references
Select a source entry to see its version, licence, locators and the threats that refer to it.
Framework mappingsThe framework mappings show which reference belongs to which topic group.
The number counts references from the threats to the source entry, not the size or the weight of the document. Several entries can belong to the same document when they point to different places within it; the locator is then shown before the title.
Versatile AI Risk Assessment is an aid for structuring AI risks and making them transparent. It does not replace legal or professional advice and makes no binding decisions.
The same data, a different question
Which provision applies, what it does not reach and which primary source the catalogue relies on.
-
Framework mappings
Where is this anchored professionally and legally?
For compliance, legal, internal audit and assurance
-
Coverage gaps
What does my framework not reach?
For anyone choosing a framework or already committed to one
- Threat pathway How does harm arise?
- Lifecycle When does which risk arise?
- Threat comparison Where does the line between two run?
- System context Which threats affect my system?
- Architecture change What does a rebuild trigger?
- Effect matrix How and where do mitigations take effect?
- Ownership Who has to act?
From the analysis to the assessment
Four short sections along the EU AI Act for a first, non‑binding orientation of your system.
To the quick checkThe full assessment with system context, threat selection and evidence tracking, free of charge in the browser.
To the live demo