All 52 threats in full: description, impact, example, mitigations and verified sources.
To the catalogueThe 265 mitigations by control type and topic group
The control type names what kind of mitigation it is, and with it usually which part of the organisation has to implement it. The switch for the complementary types makes the difference visible: both ways of counting are correct; they simply answer different questions.
Who it is for: For leadership, security ownership and anyone who has to assign responsibilities
Ownership
Select a control type or a bar segment to see the mitigations behind it with their full classification.
Effect matrixThe effect matrix shows at which implementation level these mitigations act.
The control type describes what kind of mitigation it is, not how costly or how effective it is. Neither an effort distribution nor a staffing plan can be derived from the share.
Versatile AI Risk Assessment is an aid for structuring AI risks and making them transparent. It does not replace legal or professional advice and makes no binding decisions.
The same data, a different question
Where mitigations take hold, at which level they act and which part of the organisation has to implement them.
- Threat pathway How does harm arise?
- Lifecycle When does which risk arise?
- Threat comparison Where does the line between two run?
- System context Which threats affect my system?
- Architecture change What does a rebuild trigger?
- Framework mappings Where is this anchored professionally and legally?
- Coverage gaps What does my framework not reach?
- Evidence base What is this based on?
From the analysis to the assessment
Four short sections along the EU AI Act for a first, non‑binding orientation of your system.
To the quick checkThe full assessment with system context, threat selection and evidence tracking, free of charge in the browser.
To the live demo