A versioned record of what can go wrong with an AI system and what is done about it: data flows and trust boundaries, threats per element from STRIDE and AI-specific catalogues, a decision on each, and the test that proves each mitigation. It answers the four threat-modelling questions, ending with whether the job was done well enough 1.
- Developed in
- ch. 15, Threat modelling the deployed system
ch. 05, Pattern: AI Threat Model - Chapters
- ch. 05, Patterns · ch. 14, Development · ch. 15, Deployment · ch. 23, AI Agents
- Contrast with
- Red teaming
- Source
- 1 numbered reference, listed below
Where it is used
15 chapters of the Body of Knowledge use the term. Each link opens the first section that does.
- 00 · Preface Who should read this 1 mention
- 02 · Why Now The evidence 2 mentions
- 03 · Values & Principles The six principles 2 mentions
- 05 · Patterns Pattern: AI Threat Model 1 mention
- 06 · The Role What the role owns, by workflow 1 mention
- 08 · Regulatory Map EU AI Act, post-Omnibus 4 mentions
- 10 · Reading List Regulation and standards 2 mentions
- 11 · AI Defined Eight characteristics that break classic IT governance 2 mentions
- 12 · Governance Program The stakeholder map 6 mentions
- 13 · Risk Management Risk, defined for engineers 2 mentions
- 14 · Development The technical file 1 mention
- 15 · Deployment Model types and deployment options 1 mention
- 19 · Privacy & AI Does a model contain personal data? 1 mention
- 22 · Principles & Standards NIST AI RMF 1.0 in depth 3 mentions
- 23 · AI Agents Opening 1 mention
Patterns that use this term
5 pattern pages use the term, most mentions first.
- AI Threat Model 6 mentions
- Adversarial Red-Team Suite 2 mentions
- Use-Case Intake & Risk Tiering 1 mention
- Dataset Admission Gate 1 mention
- Model Artefact Integrity 1 mention
Related terms
Sources
- [1] Threat Modeling Manifesto (threat modelling as analysing representations of a system to highlight concerns about security and privacy characteristics; four key questions). Threat Modeling Manifesto working group. n.d. (accessed 2026-09-25). https://www.threatmodelingmanifesto.org/ (verified: primary)
Definitions of legal terms paraphrase the cited text, which governs. Dated statements are as of .