Versatile AI Risk Assessment

Source directoryEuropean Union (EUR-Lex)OJ L 2024/1689, 12.07.2024

Regulation (EU) 2024/1689 (Artificial Intelligence Act), authentic Official Journal text

“Regulation (EU) 2024/1689 (Artificial Intelligence Act), authentic Official Journal text”. Publisher: European Union (EUR-Lex). Version used: OJ L 2024/1689, 12.07.2024. The Versatile AI Risk Assessment threat catalogue backs 51 of its 52 threats with this document, at 15 verified locations.

As of: July 2026 · Catalogue version 2026.07.17.3

Document details

Publisher
European Union (EUR-Lex)
Version used
OJ L 2024/1689, 12.07.2024
Year
not stated
Licence
not stated
Framework
EU AI Act

Open the original document at the publisher External link; the publisher’s version always takes precedence.

References in the catalogue (15)

Every row states the clause, its title, the exact location in the document and the threats that refer to it.

Clauses of this document with the threats that reference them
Clause Title and location Referencing threats
Article 13(1), 13(3)(b)(ii), (iv), (v) Transparency and provision of information to deployers Article 13(1), 13(3)(b)(ii), (iv), (v) Sensitive Information DisclosureExfiltration from ML ApplicationOverrelianceFactual Inconsistencies (Hallucinations)
Article 14(4)(b) Human oversight Article 14(4)(b) Overreliance
Article 14(4)(d) Human oversight Article 14(4)(d); for automation bias, Article 14(4)(b) Prompt Injection – DirectPrompt Injection – IndirectInsecure Tool DesignExcessive AgencyAgentic AI / Autonomous AgentsMCP Hijacking (Model Context Protocol)
Article 15(5) Accuracy, robustness and cybersecurity Article 15(5), including the express references to data/model poisoning, adversarial examples/evasion, confidentiality attacks and model flaws Agent Memory Poisoning (Persistent Context)Insecure Inter-Agent Communication (A2A/MCP)
Article 25(4) Responsibilities along the AI value chain Article 25(4) Supply Chain – InfrastructureSupply Chain – ModelsSupply Chain – DatasetsRAG-Specific Attacks (Document Poisoning)Middleware Exploits (AI Framework Attacks)
Article 26(5) Obligations of deployers of high-risk AI systems Article 26(5) Adversarial InputsModel Denial of ServiceCost Harvesting / RepurposingApplication Denial of ServiceAgentic AI / Autonomous AgentsModel Drift & DegradationAgent Memory Poisoning (Persistent Context)
Article 4 AI literacy Article 4 OverrelianceShadow AI (Unsanctioned AI Service Use)
Article 5(1)(a) Prohibited AI practices Article 5(1)(a); where the catalogue cites exploitation, compare Article 5(1)(b) Unethical ActionsSocial EngineeringFraudDisinformation
Article 50(2), 50(4) Transparency obligations for providers and deployers of certain AI systems Article 50(2) and 50(4) Disinformation
Article 53(1)(a) Obligations for providers of general-purpose AI models Article 53(1)(a) and Annex XI Supply Chain – InfrastructureSupply Chain – ModelsSupply Chain – DatasetsBackdoor ML ModelSleepy Agent (Time/Event-Triggered Hidden Instructions)
Article 53(1)(d) Obligations for providers of general-purpose AI models Article 53(1)(d) Supply Chain – DatasetsTraining Data PoisoningTargeted Poisoning / Label Poisoning
Article 55(1)(a) Obligations of providers of general-purpose AI models with systemic risk Article 55(1)(a) Training Data PoisoningTargeted Poisoning / Label PoisoningBackdoor ML ModelSleepy Agent (Time/Event-Triggered Hidden Instructions)Adversarial InputsPrompt Injection – DirectPrompt Injection – IndirectJailbreaksMeta Prompt ExtractionPrivacy AttacksMisalignmentAgentic AI / Autonomous AgentsMultimodal Attacks
Article 55(1)(b) Obligations of providers of general-purpose AI models with systemic risk Article 55(1)(b) JailbreaksSensitive Information DisclosureHate Speech and DiscriminationSexual ContentViolence / Unsafe ActionsControversial TopicsIllegal ActivitiesSelf-harmHarassmentUnethical ActionsSocial EngineeringFraudMalicious SoftwareDisinformationMisalignmentModel Drift & Degradation
Article 55(1)(d) Obligations of providers of general-purpose AI models with systemic risk Article 55(1)(d) Supply Chain – InfrastructureSupply Chain – ModelsModel TheftModel Denial of ServiceCost Harvesting / RepurposingExfiltration from ML ApplicationApplication VulnerabilitiesApplication Denial of ServiceMultimodal AttacksModel ReconnaissanceMiddleware Exploits (AI Framework Attacks)Side-Channel Attacks (Timing Analysis)
Article 9(1), 9(2)(a), 9(2)(d) Risk management system Article 9(1), 9(2)(a), 9(2)(d), read with Article 9(3) Training Data PoisoningBackdoor ML ModelSleepy Agent (Time/Event-Triggered Hidden Instructions)Adversarial InputsJailbreaksModel Denial of ServiceCost Harvesting / RepurposingExfiltration from ML ApplicationInsecure Output HandlingInsecure Tool DesignApplication VulnerabilitiesApplication Denial of ServiceExcessive AgencyControversial TopicsUnethical ActionsSocial EngineeringMalicious SoftwareFactual Inconsistencies (Hallucinations)MisalignmentAgentic AI / Autonomous AgentsRAG-Specific Attacks (Document Poisoning)Multimodal AttacksMiddleware Exploits (AI Framework Attacks)Cross-Tenant Leakage (Multi-Tenant Vector DB)MCP Hijacking (Model Context Protocol)Side-Channel Attacks (Timing Analysis)Graph-RAG Poisoning (Knowledge Graph Injection)Agent Memory Poisoning (Persistent Context)Insecure Inter-Agent Communication (A2A/MCP)

This page does not reproduce the text of the standards. It states the identifier, title and location of the clause; the wording itself is in the original document. The mappings are taxonomic and not evidence of compliance.

Threats referencing this document (51)

Grouped by topic. Every entry leads to the full threat page.

Malicious Use for Attacks, Fraud and Disinformation

More documents from the same publisher

All documents by European Union (EUR-Lex) cited in the catalogue.

From the reference to the assessment

The full catalogue states the mitigations, the possible impact and every verified location for each threat. The live demo runs locally in your browser, with no sign-up.

Cite this page

For reports, policies or internal documents; the link leads directly to this source page.

“Regulation (EU) 2024/1689 (Artificial Intelligence Act), authentic Official Journal text” (European Union (EUR-Lex)). References in the AI threat catalogue, Versatile AI Risk Assessment, as of July 2026.
https://www.versatile-ai-risk-assessment.com/en/wissensbasis/sources/eu-ai-act-2024-1689/

← Back to the source directory