Threat model (AI)

A versioned record of what can go wrong with an AI system and what is done about it: data flows and trust boundaries, threats per element from STRIDE and AI-specific catalogues, a decision on each, and the test that proves each mitigation. It answers the four threat-modelling questions, ending with whether the job was done well enough 1.

Developed in
ch. 15, Threat modelling the deployed system
ch. 05, Pattern: AI Threat Model
Chapters
ch. 05, Patterns · ch. 14, Development · ch. 15, Deployment · ch. 23, AI Agents
Contrast with
Red teaming
Source
1 numbered reference, listed below

Where it is used

15 chapters of the Body of Knowledge use the term. Each link opens the first section that does.

Patterns that use this term

5 pattern pages use the term, most mentions first.

Sources

  1. [1] Threat Modeling Manifesto (threat modelling as analysing representations of a system to highlight concerns about security and privacy characteristics; four key questions). Threat Modeling Manifesto working group. n.d. (accessed 2026-09-25). https://www.threatmodelingmanifesto.org/ (verified: primary)

Definitions of legal terms paraphrase the cited text, which governs. Dated statements are as of .

Cite this term

García Aibar, J. (2026). Threat model (AI). In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0), Glossary. https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/glossary/threat-model-ai. CC BY 4.0

BibTeX

@misc{aige2026threatmodelai,
  author  = {Jorge García Aibar},
  title   = {{Threat model (AI)}},
  note    = {Glossary, AI Governance Engineering: The Thesis \& Body of Knowledge, version 0.5.0},
  year    = {2026},
  doi     = {10.5281/zenodo.22956197},
  url     = {https://aigovernanceengineer.com/glossary/threat-model-ai}
}