Versatile AI Risk Assessment
Knowledge base

Threat catalogue

Threats to AI systems with a description, possible impact, an example, recommended mitigations by control type and the verified references in the primary sources. One row per threat, sortable by every column; every threat also has its own page. The mappings to OWASP, NIST AI RMF, MITRE ATLAS, BSI, BIML, the EU AI Act and GDPR are taxonomic and not evidence of compliance.

All threats with mitigations and verified references

Threats mapped per framework
No filter set, the list shows the complete collection.52 of 52 threats

All threats of the catalogue, sortable by every column
Reading list
T-001 Supply Chain and Provenance Supply Chain 4 13
T-002 Supply Chain and Provenance Supply Chain 4 15
T-003 Supply Chain and Provenance Supply Chain 4 16
T-004 Model and Training Data Manipulation Development 4 15
T-005 Model and Training Data Manipulation Development 4 11
T-006 Model and Training Data Manipulation Development 4 15
T-007 Model and Training Data Manipulation Development 6 12
T-008 Attacks on the Running Model and Service Production 5 8
T-009 Attacks on the Running Model and Service Production 4 14
T-010 Prompt Attacks and Guardrail Evasion Production 4 10
T-011 Prompt Attacks and Guardrail Evasion Production 5 12
T-012 Prompt Attacks and Guardrail Evasion Production 4 11
T-013 Prompt Attacks and Guardrail Evasion Production 4 8
T-014 Attacks on the Running Model and Service Production 5 10
T-015 Attacks on the Running Model and Service Production 5 5
T-016 Privacy and Data Leakage Production 5 19
T-017 Privacy and Data Leakage Production 4 18
T-018 Privacy and Data Leakage Production 5 17
T-019 Application and Integration Security Production 4 8
T-020 Application and Integration Security Production 5 8
T-021 Application and Integration Security Production 5 7
T-022 Attacks on the Running Model and Service Production 5 6
T-023 Agentic and Autonomous AI Production 5 7
T-024 Reliability and Responsible Use Production 5 11
T-025 Harmful Content Production 5 9
T-026 Harmful Content Production 4 2
T-027 Harmful Content Production 5 5
T-028 Harmful Content Production 5 5
T-029 Harmful Content Production 5 6
T-030 Harmful Content Production 5 7
T-031 Harmful Content Production 5 4
T-032 Harmful Content Production 5 4
T-033 Harmful Content Production 5 5
T-034 Malicious Use for Attacks, Fraud and Disinformation Production 5 7
T-035 Malicious Use for Attacks, Fraud and Disinformation Production 5 6
T-036 Malicious Use for Attacks, Fraud and Disinformation Production 5 6
T-037 Malicious Use for Attacks, Fraud and Disinformation Production 5 8
T-038 Reliability and Responsible Use Production 6 10
T-039 Agentic and Autonomous AI Production 5 5
T-040 Agentic and Autonomous AI Production 7 13
T-041 Application and Integration Security Production 7 11
T-042 Reliability and Responsible Use Production 7 9
T-043 Prompt Attacks and Guardrail Evasion Production 6 11
T-044 Attacks on the Running Model and Service Production 6 12
T-045 Application and Integration Security Production 7 9
T-046 Privacy and Data Leakage Production 6 10
T-047 Application and Integration Security Production 6 14
T-048 Attacks on the Running Model and Service Production 6 7
T-049 Application and Integration Security Production 7 5
T-050 Reliability and Responsible Use Production 7 7
T-051 Agentic and Autonomous AI Production 5 7
T-052 Agentic and Autonomous AI Production 4 6

Catalogue version v2026.07.17.3 · 486 verified framework relations from 21 primary sources.

Related

Look up and continue

Glossary

The terms behind the threats: prompt injection, agentic system, residual risk and more, each with a short version and a reference into the catalogue.

To the glossary
Frameworks

What stands behind every mapping: what a framework governs, which documents represent it, how far it reaches and which threats it does not reach.

To the frameworks
Source directory

The verified primary sources with version, licence and the threats that reference them. Every reference was checked against the original document.

To the directory
Interactive analyses

The same catalogue from ten angles: the pathway of a threat, the link to your own system type, ownership and the gaps a framework leaves.

Open the analyses

Live demo: assess a threat yourself