Versatile AI Risk Assessment

Source directoryBundesamt für Sicherheit in der Informationstechnik (BSI)2.0

Generative KI-Modelle: Chancen und Risiken für Industrie und Behörden

“Generative KI-Modelle: Chancen und Risiken für Industrie und Behörden”. Publisher: Bundesamt für Sicherheit in der Informationstechnik (BSI). Version used: 2.0. The Versatile AI Risk Assessment threat catalogue backs 40 of its 52 threats with this document, at 28 verified locations.

As of: July 2026 · Catalogue version 2026.07.17.3

Document details

Publisher
Bundesamt für Sicherheit in der Informationstechnik (BSI)
Version used
2.0
Year
not stated
Licence
not stated
Framework
BSI

Open the original document at the publisher External link; the publisher’s version always takes precedence.

References in the catalogue (28)

Every row states the clause, its title, the exact location in the document and the threats that refer to it.

Clauses of this document with the threats that reference them
Clause Title and location Referencing threats
R1 Abhängigkeit vom entwickelnden/betreibenden Unternehmen (Text, Bild, Video) Kap. 4, R1, p. 13 Supply Chain – InfrastructureSupply Chain – Models
R10 Erzeugung ver- und gefälschter Inhalte (Text, Bild, Video) Kap. 4, R10, p. 18 Illegal ActivitiesFraudDisinformation
R11 Vortäuschen einer (medialen) Identität (Text, Bild, Video) Kap. 4, R11, p. 19 Social EngineeringFraud
R12 Wissenssammlung und -aufbereitung im Kontext krimineller Aktivitäten (Text, Bild) Kap. 4, R12, p. 20 Illegal ActivitiesMalicious SoftwareModel Reconnaissance
R13 Re-Identifizierung von Personen aus anonymisierten Daten (Text, Bild, Video) Kap. 4, R13, p. 21 Privacy Attacks
R14 Generierung und Verbesserung von Malware (Text) Kap. 4, R14, p. 22 Malicious Software
R15 Platzierung von Malware (Text) Kap. 4, R15, p. 22 Factual Inconsistencies (Hallucinations)
R16 RCE-Angriffe (Text) Kap. 4, R16, p. 24 Insecure Output Handling
R17 Vergiftung der Trainingsdaten (Data Poisoning) (Text, Bild, Video) Kap. 4, R17, p. 25 Supply Chain – DatasetsTraining Data PoisoningTargeted Poisoning / Label Poisoning
R18 Vergiftung von hinterlegten Wissensdaten (Knowledge Poisoning) (Text, Bild, Video) Kap. 4, R18, p. 26 RAG-Specific Attacks (Document Poisoning)Graph-RAG Poisoning (Knowledge Graph Injection)
R19 Vergiftung des Modells selbst (Model/Weight Poisoning) (Text, Bild, Video) Kap. 4, R19, p. 26 Supply Chain – ModelsBackdoor ML ModelSleepy Agent (Time/Event-Triggered Hidden Instructions)
R2 Fehlende Vertraulichkeit eingegebener Daten (Text, Bild, Video) Kap. 4, R2, p. 14 Privacy AttacksSensitive Information DisclosureExfiltration from ML Application
R20 Vergiftung über das Bewertungsmodell (Text, Bild, Video) Kap. 4, R20, p. 26 Training Data PoisoningBackdoor ML ModelMisalignment
R21 Vergiftung über vorverarbeitende Komponenten (Text, Bild, Video) Kap. 4, R21, p. 27 Training Data Poisoning
R22 Rekonstruktion von Trainingsdaten (Text, Bild, Video) Kap. 4, R22, p. 28 Privacy Attacks
R23 Embedding Inversion (Text, Bild, Video) Kap. 4, R23, p. 28 Privacy AttacksCross-Tenant Leakage (Multi-Tenant Vector DB)
R24 Modelldiebstahl (Text, Bild, Video) Kap. 4, R24, p. 29 Model Theft
R25 Extraktion von Kommunikationsdaten und hinterlegten Informationen (Text, Bild, Video) Kap. 4, R25, p. 30 Meta Prompt ExtractionSensitive Information DisclosureModel Reconnaissance
R26 Direkte Manipulationen im Prompt (Text, Bild, Video) Kap. 4, R26, p. 31 Prompt Injection – DirectJailbreaks
R27 Störung der automatisierten Verarbeitung von Inhalten (Text) Kap. 4, R27, p. 33 Adversarial Inputs
R28 Indirect Prompt Injections (Text) Kap. 4, R28, p. 33 Prompt Injection – IndirectModel Denial of ServiceExfiltration from ML ApplicationInsecure Tool DesignExcessive AgencyAgentic AI / Autonomous AgentsMCP Hijacking (Model Context Protocol)
R3 Fehlerhafte Reaktion auf Eingaben (Text, Bild, Video) Kap. 4, R3, p. 14 Adversarial InputsPrompt Injection – DirectPrompt Injection – IndirectExcessive Agency
R4 Fehlende Ausgabequalität (Text, Bild, Video) Kap. 4, R4, p. 15 Factual Inconsistencies (Hallucinations)
R5 Problematische und verzerrte Ausgaben (Text, Bild, Video) Kap. 4, R5, p. 16 Hate Speech and DiscriminationProfanitySexual ContentViolence / Unsafe ActionsHarassmentDisinformation
R6 Fehlende Sicherheit von generiertem Code und codeähnlichen Texten (Text) Kap. 4, R6, p. 16 Insecure Output Handling
R7 Fehlende Reproduzierbarkeit und Erklärbarkeit (Text, Bild, Video) Kap. 4, R7, p. 17 Prompt Injection – Indirect
R8 Automation Bias (Text, Bild, Video) Kap. 4, R8, p. 17 Overreliance
R9 Selbstverstärkende Effekte und Model Collapse (Text, Bild, Video) Kap. 4, R9, p. 18 Model Drift & Degradation

This page does not reproduce the text of the standards. It states the identifier, title and location of the clause; the wording itself is in the original document. The mappings are taxonomic and not evidence of compliance.

Threats referencing this document (40)

Grouped by topic. Every entry leads to the full threat page.

Agentic and Autonomous AI

Attacks on the Running Model and Service

Malicious Use for Attacks, Fraud and Disinformation

Prompt Attacks and Guardrail Evasion

From the reference to the assessment

The full catalogue states the mitigations, the possible impact and every verified location for each threat. The live demo runs locally in your browser, with no sign-up.

Cite this page

For reports, policies or internal documents; the link leads directly to this source page.

“Generative KI-Modelle: Chancen und Risiken für Industrie und Behörden” (Bundesamt für Sicherheit in der Informationstechnik (BSI)). References in the AI threat catalogue, Versatile AI Risk Assessment, as of July 2026.
https://www.versatile-ai-risk-assessment.com/en/wissensbasis/sources/bsi-generative-ai-models/

← Back to the source directory