Versatile AI Risk Assessment

What changes when the system setup changes

For every system type, the catalogue states whether a threat always has to be considered or only case by case. Choose the current and the new system type; the three columns show what is added, what stays and what drops out.

Who it is for: For architecture, product ownership and anyone facing a change to the system boundary

Architecture change

Moving from LLM API integration to Agentic AI adds 15 threats, keeps 22 and drops 3.

15newly addedof which 13 only case by case before
22stay
3drop outof which 3 still case by case
37/52always considered in the new system type

Newly added15

always considered in the new system type, not in the current one

Stays22

always considered in both system types

Drops out3

always considered in the current system type, only case by case or not at all in the new one

Select a threat from one of the three columns to see its mitigations.

What the new system type draws attention to · Agentic AI

Systems with tool use, memory, planning steps, or autonomous execution need a stronger focus on agency, tool safety, session context, and human oversight.

Tool and MCP trustAutonomy boundariesMemory/RAG contextAbuse of autonomous workflowsOversight and escalation

Review questions from the catalogue · 3
  • Which tools can the agent invoke and with which privileges?
  • Which actions require explicit human approval?
  • Can external or stored context influence future agent decisions?

System contextThe system context view shows the full catalogue from the perspective of the new system type.

The file shows the current state including any filters and carries the note, catalogue version and source.

“Always consider” means the catalogue includes the threat for this system type in every case. “Case by case” means it depends on further characteristics of the system. A threat that drops out is not thereby ruled out.

Versatile AI Risk Assessment is an aid for structuring AI risks and making them transparent. It does not replace legal or professional advice and makes no binding decisions.

Placing your own system

The same data, a different question

Which part of the catalogue applies to a concrete system boundary and what changes on a rebuild.

  1. Preview of the analysis: System context System context Which threats affect my system? For architecture, product ownership and anyone assessing a concrete system
Understanding threats
Planning mitigations
Checking frameworks and evidence

Overview of all ten analyses

Related
Threat catalogue

All 52 threats in full: description, impact, example, mitigations and verified sources.

To the catalogue
EU AI Act quick check

Four short sections along the EU AI Act for a first, non‑binding orientation of your system.

To the quick check
Assess it yourself

The full assessment with system context, threat selection and evidence tracking, free of charge in the browser.

To the live demo