All 52 threats in full: description, impact, example, mitigations and verified sources.
To the catalogueWhat changes when the system setup changes
For every system type, the catalogue states whether a threat always has to be considered or only case by case. Choose the current and the new system type; the three columns show what is added, what stays and what drops out.
Who it is for: For architecture, product ownership and anyone facing a change to the system boundary
Architecture change
Newly added15
always considered in the new system type, not in the current one
Stays22
always considered in both system types
Drops out3
always considered in the current system type, only case by case or not at all in the new one
Select a threat from one of the three columns to see its mitigations.
What the new system type draws attention to · Agentic AI
Systems with tool use, memory, planning steps, or autonomous execution need a stronger focus on agency, tool safety, session context, and human oversight.
Tool and MCP trustAutonomy boundariesMemory/RAG contextAbuse of autonomous workflowsOversight and escalation
Review questions from the catalogue · 3
- Which tools can the agent invoke and with which privileges?
- Which actions require explicit human approval?
- Can external or stored context influence future agent decisions?
“Always consider” means the catalogue includes the threat for this system type in every case. “Case by case” means it depends on further characteristics of the system. A threat that drops out is not thereby ruled out.
Versatile AI Risk Assessment is an aid for structuring AI risks and making them transparent. It does not replace legal or professional advice and makes no binding decisions.
The same data, a different question
Which part of the catalogue applies to a concrete system boundary and what changes on a rebuild.
- Threat pathway How does harm arise?
- Lifecycle When does which risk arise?
- Threat comparison Where does the line between two run?
- Effect matrix How and where do mitigations take effect?
- Ownership Who has to act?
- Framework mappings Where is this anchored professionally and legally?
- Coverage gaps What does my framework not reach?
- Evidence base What is this based on?
From the analysis to the assessment
Four short sections along the EU AI Act for a first, non‑binding orientation of your system.
To the quick checkThe full assessment with system context, threat selection and evidence tracking, free of charge in the browser.
To the live demo