Versatile AI Risk Assessment

AI threat catalogueApplication and Integration SecurityProduction

RAG-Specific Attacks (Document Poisoning)

Attackers plant prepared documents in the knowledge base an AI system draws on via RAG (retrieval-augmented generation, looking up internal documents before answering). When retrieved, the system adopts the false content or hidden commands.

As of: July 2026 · Catalogue version 2026.07.17.3 · 7 mitigations · 11 verified sources

Description

Many corporate AI assistants ground their answers in an internal knowledge base built from wikis, drives, emails or tickets. Attackers use any path by which content enters this knowledge base: a public channel, an incoming email, a shared document, a file upload. There they place content designed to surface for specific queries, containing false facts or hidden instructions (indirect prompt injection). The model treats retrieved text as trustworthy, produces the intended false answer or follows the instruction. Attackers need no access to the model or its training for this.

Possible impact

False answers appear with the credibility of internal sources and feed into decisions. Hidden instructions can leak confidential data or trigger actions. The poisoning persists in the knowledge base and affects every future query until it is found and removed; business decisions, data protection and compliance are all at stake.

Example

An attacker sends an inconspicuous email with hidden instructions to the accounting team. The AI assistant ingests it into its knowledge base; when an employee later asks for a supplier's bank details, the assistant returns the attacker's account.

Recommended mitigations (7)

Every mitigation states its control type, effect, implementation level and the reason for the classification.

Framework mappings

Verified locations in OWASP, NIST AI RMF, MITRE ATLAS, the EU AI Act and further frameworks. The mappings are taxonomic, not evidence of compliance.

OWASP LLM Top 10 ASI06:2026 · LLM01:2025 · LLM04:2025 · LLM08:2025NIST AI RMF NISTAML.015 · NISTAML.027MITRE ATLAS AML.T0051EU AI Act Article 25(4) · Article 9(1), 9(2)(a), 9(2)(d)BSI R18BIML BIML-LLM raw:10

Verified references (11)

Every reference states the framework, the exact location and the publishing organisation.

Terms on this page

Glossary terms that occur in this entry. Every link leads to the full explanation.

More entries from the topic group Application and Integration Security.

Assess this threat in your own system

The live demo contains all 52 threats of this catalogue, including the EU AI Act and GDPR assessment. The free single modules cover AI risk, the EU AI Act and GDPR. No sign-up; the assessment runs locally in your browser.

Cite this entry

For reports, policies or internal documents; the link leads directly to this entry.

“RAG-Specific Attacks (Document Poisoning)”. Versatile AI Risk Assessment, AI threat catalogue, as of July 2026.
https://www.versatile-ai-risk-assessment.com/en/wissensbasis/threats/rag-document-poisoning/

← Back to the full catalogue