Source directoryBundesamt für Sicherheit in der Informationstechnik (BSI)2.0
Generative KI-Modelle: Chancen und Risiken für Industrie und Behörden
“Generative KI-Modelle: Chancen und Risiken für Industrie und Behörden”. Publisher: Bundesamt für Sicherheit in der Informationstechnik (BSI). Version used: 2.0. The Versatile AI Risk Assessment threat catalogue backs 40 of its 52 threats with this document, at 28 verified locations.
Document details
- Publisher
- Bundesamt für Sicherheit in der Informationstechnik (BSI)
- Version used
- 2.0
- Year
- not stated
- Licence
- not stated
- Framework
- BSI
Open the original document at the publisher External link; the publisher’s version always takes precedence.
References in the catalogue (28)
Every row states the clause, its title, the exact location in the document and the threats that refer to it.
| Clause | Title and location | Referencing threats |
|---|---|---|
R1 |
Abhängigkeit vom entwickelnden/betreibenden Unternehmen (Text, Bild, Video) Kap. 4, R1, p. 13 | Supply Chain – InfrastructureSupply Chain – Models |
R10 |
Erzeugung ver- und gefälschter Inhalte (Text, Bild, Video) Kap. 4, R10, p. 18 | Illegal ActivitiesFraudDisinformation |
R11 |
Vortäuschen einer (medialen) Identität (Text, Bild, Video) Kap. 4, R11, p. 19 | Social EngineeringFraud |
R12 |
Wissenssammlung und -aufbereitung im Kontext krimineller Aktivitäten (Text, Bild) Kap. 4, R12, p. 20 | Illegal ActivitiesMalicious SoftwareModel Reconnaissance |
R13 |
Re-Identifizierung von Personen aus anonymisierten Daten (Text, Bild, Video) Kap. 4, R13, p. 21 | Privacy Attacks |
R14 |
Generierung und Verbesserung von Malware (Text) Kap. 4, R14, p. 22 | Malicious Software |
R15 |
Platzierung von Malware (Text) Kap. 4, R15, p. 22 | Factual Inconsistencies (Hallucinations) |
R16 |
RCE-Angriffe (Text) Kap. 4, R16, p. 24 | Insecure Output Handling |
R17 |
Vergiftung der Trainingsdaten (Data Poisoning) (Text, Bild, Video) Kap. 4, R17, p. 25 | Supply Chain – DatasetsTraining Data PoisoningTargeted Poisoning / Label Poisoning |
R18 |
Vergiftung von hinterlegten Wissensdaten (Knowledge Poisoning) (Text, Bild, Video) Kap. 4, R18, p. 26 | RAG-Specific Attacks (Document Poisoning)Graph-RAG Poisoning (Knowledge Graph Injection) |
R19 |
Vergiftung des Modells selbst (Model/Weight Poisoning) (Text, Bild, Video) Kap. 4, R19, p. 26 | Supply Chain – ModelsBackdoor ML ModelSleepy Agent (Time/Event-Triggered Hidden Instructions) |
R2 |
Fehlende Vertraulichkeit eingegebener Daten (Text, Bild, Video) Kap. 4, R2, p. 14 | Privacy AttacksSensitive Information DisclosureExfiltration from ML Application |
R20 |
Vergiftung über das Bewertungsmodell (Text, Bild, Video) Kap. 4, R20, p. 26 | Training Data PoisoningBackdoor ML ModelMisalignment |
R21 |
Vergiftung über vorverarbeitende Komponenten (Text, Bild, Video) Kap. 4, R21, p. 27 | Training Data Poisoning |
R22 |
Rekonstruktion von Trainingsdaten (Text, Bild, Video) Kap. 4, R22, p. 28 | Privacy Attacks |
R23 |
Embedding Inversion (Text, Bild, Video) Kap. 4, R23, p. 28 | Privacy AttacksCross-Tenant Leakage (Multi-Tenant Vector DB) |
R24 |
Modelldiebstahl (Text, Bild, Video) Kap. 4, R24, p. 29 | Model Theft |
R25 |
Extraktion von Kommunikationsdaten und hinterlegten Informationen (Text, Bild, Video) Kap. 4, R25, p. 30 | Meta Prompt ExtractionSensitive Information DisclosureModel Reconnaissance |
R26 |
Direkte Manipulationen im Prompt (Text, Bild, Video) Kap. 4, R26, p. 31 | Prompt Injection – DirectJailbreaks |
R27 |
Störung der automatisierten Verarbeitung von Inhalten (Text) Kap. 4, R27, p. 33 | Adversarial Inputs |
R28 |
Indirect Prompt Injections (Text) Kap. 4, R28, p. 33 | Prompt Injection – IndirectModel Denial of ServiceExfiltration from ML ApplicationInsecure Tool DesignExcessive AgencyAgentic AI / Autonomous AgentsMCP Hijacking (Model Context Protocol) |
R3 |
Fehlerhafte Reaktion auf Eingaben (Text, Bild, Video) Kap. 4, R3, p. 14 | Adversarial InputsPrompt Injection – DirectPrompt Injection – IndirectExcessive Agency |
R4 |
Fehlende Ausgabequalität (Text, Bild, Video) Kap. 4, R4, p. 15 | Factual Inconsistencies (Hallucinations) |
R5 |
Problematische und verzerrte Ausgaben (Text, Bild, Video) Kap. 4, R5, p. 16 | Hate Speech and DiscriminationProfanitySexual ContentViolence / Unsafe ActionsHarassmentDisinformation |
R6 |
Fehlende Sicherheit von generiertem Code und codeähnlichen Texten (Text) Kap. 4, R6, p. 16 | Insecure Output Handling |
R7 |
Fehlende Reproduzierbarkeit und Erklärbarkeit (Text, Bild, Video) Kap. 4, R7, p. 17 | Prompt Injection – Indirect |
R8 |
Automation Bias (Text, Bild, Video) Kap. 4, R8, p. 17 | Overreliance |
R9 |
Selbstverstärkende Effekte und Model Collapse (Text, Bild, Video) Kap. 4, R9, p. 18 | Model Drift & Degradation |
This page does not reproduce the text of the standards. It states the identifier, title and location of the clause; the wording itself is in the original document. The mappings are taxonomic and not evidence of compliance.
Threats referencing this document (40)
Grouped by topic. Every entry leads to the full threat page.
Agentic and Autonomous AI
Application and Integration Security
Attacks on the Running Model and Service
Harmful Content
Malicious Use for Attacks, Fraud and Disinformation
Model and Training Data Manipulation
Privacy and Data Leakage
Prompt Attacks and Guardrail Evasion
Reliability and Responsible Use
Supply Chain and Provenance
From the reference to the assessment
The full catalogue states the mitigations, the possible impact and every verified location for each threat. The live demo runs locally in your browser, with no sign-up.
Cite this page
For reports, policies or internal documents; the link leads directly to this source page.
“Generative KI-Modelle: Chancen und Risiken für Industrie und Behörden” (Bundesamt für Sicherheit in der Informationstechnik (BSI)). References in the AI threat catalogue, Versatile AI Risk Assessment, as of July 2026. https://www.versatile-ai-risk-assessment.com/en/wissensbasis/sources/bsi-generative-ai-models/