Versatile AI Risk Assessment

Frameworks Guidance from a public authority Bundesamt für Sicherheit in der Informationstechnik (BSI)

BSI guidance on generative AI

The German cybersecurity authority on generative AI models: risks from use, misuse and attacks, each with mitigations.

As of: July 2026 · Catalogue version 2026.07.17.3

What this framework governs

The Federal Office for Information Security (BSI) is Germany’s federal cybersecurity authority and the point of reference for information security for companies and public administration in Germany.

Its paper on generative AI models, addressed to industry and public authorities, describes where such models carry risks in proper use, through misuse and through targeted attacks, and names mitigations for each risk.

It explicitly addresses companies and public bodies that intend to deploy generative AI, which makes it directly tailored to practical use.

Mappings in the threat catalogue

BSI guidance on generative AI. Publisher: Bundesamt für Sicherheit in der Informationstechnik (BSI). The Versatile AI Risk Assessment threat catalogue reaches 40 of its 52 threats through this framework, backed by one document at 28 locations. Mappings are documented for 40 of the 52 threats in the catalogue. The overview shows their distribution by topic group.

Supply Chain and Provenance 3 / 3
Model and Training Data Manipulation 4 / 4
Attacks on the Running Model and Service 4 / 7
Prompt Attacks and Guardrail Evasion 4 / 5
Privacy and Data Leakage 4 / 4
Application and Integration Security 5 / 7
Agentic and Autonomous AI 3 / 5
Reliability and Responsible Use 3 / 4
Harmful Content 6 / 9
Malicious Use for Attacks, Fraud and Disinformation 4 / 4

12 threats without a mapped reference

The catalogue contains no reference from this framework for these threats. This does not establish whether the original document addresses them. See the threat pages for recorded mappings to other frameworks.

Analysis: combine several frameworks and see the gaps that remain

Threats referencing this framework (40)

Grouped by topic. Every entry leads to the full threat page.

40 of 40

Agentic and Autonomous AI

3 threats

Attacks on the Running Model and Service

4 threats

Malicious Use for Attacks, Fraud and Disinformation

4 threats

Filter the catalogue by BSI guidance on generative AI

Sources used (1)

These exact versions are pinned in the catalogue. Every page states the publisher, the version used, the locations and the referencing threats.

This page does not reproduce the text of the standards. It states the identifier, title and location; the wording itself is in the original document. The mappings are taxonomic and not evidence of compliance.

Guidance on use

The guidance provides technical recommendations and is not itself a legal norm. Which measures are binding for an organisation must be assessed against the applicable requirements.

Further frameworks

The frameworks address different aspects: legal requirements, organisational risk management and technical security. Explore the further perspectives included in the catalogue.

From the framework to the assessment

The full catalogue states the mitigations, the possible impact and every verified location for each threat. The live demo runs locally in your browser, with no sign-up.

Cite this page

For reports, policies or internal documents; the link leads directly to this framework page.

“BSI guidance on generative AI” (Bundesamt für Sicherheit in der Informationstechnik (BSI)). Mappings in the AI threat catalogue, Versatile AI Risk Assessment, as of July 2026.
https://www.versatile-ai-risk-assessment.com/en/wissensbasis/frameworks/bsi-generative-ai/

← Back to the framework directory