---
title: "Threat model (AI)"
description: "A versioned record of what can go wrong with an AI system and what is done about it: data flows and trust boundaries, threats per element from STRIDE and AI-specific catalogues, a decision on each…"
canonical: https://aigovernanceengineer.com/glossary/threat-model-ai
author: "Jorge García Aibar"
license: "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)"
doi: https://doi.org/10.5281/zenodo.22956197
version: "0.5.0"
updated: 2026-09-25
---

# Threat model (AI)

A versioned record of what can go wrong with an AI system and what is done about it: data flows and trust boundaries, threats per element from STRIDE and AI-specific catalogues, a decision on each, and the test that proves each mitigation. It answers the four threat-modelling questions, ending with whether the job was done well enough [1].

- Developed in: [ch. 15, Threat modelling the deployed system](https://aigovernanceengineer.com/bok/governing-deployment#threat-modelling-the-deployed-system); [ch. 05, Pattern: AI Threat Model](https://aigovernanceengineer.com/patterns/ai-threat-model)
- Chapters: [ch. 05, Patterns](https://aigovernanceengineer.com/bok/patterns) · [ch. 14, Development](https://aigovernanceengineer.com/bok/governing-development) · [ch. 15, Deployment](https://aigovernanceengineer.com/bok/governing-deployment) · [ch. 23, AI Agents](https://aigovernanceengineer.com/bok/governing-agents)
- Contrast with: [Red teaming](https://aigovernanceengineer.com/glossary/red-teaming)
- In the glossary chapter: https://aigovernanceengineer.com/bok/glossary#t-threat-model-ai

## Sources

[1] Threat Modeling Manifesto (threat modelling as analysing representations of a system to highlight concerns about security and privacy characteristics; four key questions). Threat Modeling Manifesto working group. n.d. (accessed 2026-09-25). https://www.threatmodelingmanifesto.org/ (verified: primary)
