Versatile AI Risk Assessment

AI threat catalogueApplication and Integration SecurityProduction

Application Vulnerabilities

The software around the AI model, meaning its web interface, APIs and databases, has the same weaknesses as any other application. Attackers do not need to outwit the model if a classic security flaw opens the way into the system.

As of: July 2026 · Catalogue version 2026.07.17.3 · 5 mitigations · 7 verified sources

Description

An AI system is far more than the model: login, user management, programming interfaces (APIs), databases and server infrastructure form the application layer. This is where the long-known weaknesses of web security arise: injected scripts (XSS), manipulated database queries (SQL injection), actions forged in the name of logged-in users (CSRF) or bypassed authentication. Attackers often find such flaws from the outside with automated scans. AI projects are particularly exposed when attention is focused on the model and quickly built prototypes or newer AI frameworks go into production without hardening.

Possible impact

Through a flaw in the application layer, attackers gain access to the system and all data it processes, including user inputs, knowledge bases and credentials. The consequences range from manipulation or outage of the service to GDPR notification duties after data leaks, and for high-risk systems questions of cybersecurity conformity under the EU AI Act.

Example

A company runs its AI framework with an administration interface that is reachable from the internet without login. Attackers find the open interface, execute their own code on the servers and siphon off computing power, models and data.

Recommended mitigations (5)

Every mitigation states its control type, effect, implementation level and the reason for the classification.

Framework mappings

Verified locations in OWASP, NIST AI RMF, MITRE ATLAS, the EU AI Act and further frameworks. The mappings are taxonomic, not evidence of compliance.

NIST AI RMF Section 2.9MITRE ATLAS AML.T0049EU AI Act Article 55(1)(d) · Article 9(1), 9(2)(a), 9(2)(d)BIML BIML-LLM inference:10 · BIML-LLM inference:9 · BIML78 system:9

Verified references (7)

Every reference states the framework, the exact location and the publishing organisation.

More entries from the topic group Application and Integration Security.

Assess this threat in your own system

The live demo contains all 52 threats of this catalogue, including the EU AI Act and GDPR assessment. The free single modules cover AI risk, the EU AI Act and GDPR. No sign-up; the assessment runs locally in your browser.

Cite this entry

For reports, policies or internal documents; the link leads directly to this entry.

“Application Vulnerabilities”. Versatile AI Risk Assessment, AI threat catalogue, as of July 2026.
https://www.versatile-ai-risk-assessment.com/en/wissensbasis/threats/application-vulnerabilities/

← Back to the full catalogue