From a threat id to the test that proves the control.

A threat model is only useful when each threat ends in a control that runs and a test that would fail if the control did not. Each row here starts from an id an external catalogue gives a threat, names the patterns that control it, an example eval that tests the control, and the obligations that eval's evidence helps satisfy.

How to read a row

Read each card as one sentence: this threat is stopped by this control, built with these patterns; this check fails if the control does not work; and the result is evidence for these obligations. The step that produces the rows for your own system, from data-flow diagram to test plan, is in the Adversarial Red-Team Suite pattern; chapter 15 applies it to the deployed system and chapter 23 to agents.

  1. Threat An id from OWASP, MITRE ATLAS or NIST, and what it means in our words.
  2. Control What stops it, and the patterns that build that control.
  3. Test A named check in Inspect, promptfoo or garak, or a test you write where none of them ships one.
  4. Obligation The register rows the passing result helps evidence, with ISO/IEC 42001, CSA AICM, NIST SP 800-218A and COSAiS ids beside them.

51 threats from four catalogues

The same threat often has an id in more than one catalogue: prompt injection is LLM01:2026, AML.T0051 and NISTAML.018. Each card links its equivalents under "Same threat elsewhere", so a test tagged with one id can be traced to the others.

JSON (API) Download CSV

Filter by catalogue
Filter by stack layer

No row from OWASP Agentic 2026 sits in layer 1, Govern-as-Code. Choose another layer.

No row from MITRE ATLAS sits in layer 1, Govern-as-Code. Choose another layer.

No row from NIST AI 100-2 sits in layer 1, Govern-as-Code. Choose another layer.

No row from OWASP LLM 2026 sits in layer 5, Assurance & Continuous Compliance. Choose another layer.

No row from NIST AI 100-2 sits in layer 5, Assurance & Continuous Compliance. Choose another layer.

OWASP Top 10 for LLM Applications 2026

10 rows

Risks when the model is a component inside an application; the 2026 edition renumbers several 2025 entries. Version: 2026 (published 3 Aug 2026); OWASP GenAI Security Project 1.

OWASP Top 10 for Agentic Applications 2026

10 rows

Risks once the model acts: tools it calls, memory it carries, identities it uses and other agents it talks to. Version: 2026 (published 9 Dec 2025); OWASP GenAI Security Project 4.

MITRE ATLAS techniques

18 rows

Adversary techniques against AI systems, organised by tactic, with the mitigations ATLAS links to each. Version: data release v2026.09 (15 Sep 2026); MITRE 5.

NIST AI 100-2 E2025 attack classes

13 rows

Attacks on predictive and generative models, classed by the attacker goal they serve: availability, integrity, privacy, misuse. Version: E2025 (24 Mar 2025); NIST 6.

The control frameworks beside each row

ISO/IEC 42001 controls are cited by their Annex A id and short title only 10; the register rows they belong to are linked under "Evidence for". CSA AICM v1.1 holds 247 control objectives in 18 domains 11; rows name the domain, following the domain mapping OWASP publishes for the 2026 LLM list 2, not individual control ids. NIST SP 800-218A adds AI-specific tasks to the Secure Software Development Framework, and a row names one only where the threat enters during development 7.

NIST's Control Overlays for Securing AI Systems (COSAiS) will tailor SP 800-53 controls to five use cases. As of 2026-09-24 the project page lists a concept paper (14 Aug 2025) and an annotated outline for predictive AI (8 Jan 2026) and no overlay in final form, so rows name the use case a threat belongs to, not overlay controls 8.

Sources

Each catalogue is pinned to the version named above. ATLAS names and mitigation links were read from the release data, because the ATLAS website renders in JavaScript.

  1. [1] OWASP GenAI LLM Top 10 2026 (LLM01:2026 Prompt Injection to LLM10:2026 Improper Output Handling; resource page dated 3 Aug 2026). OWASP GenAI Security Project. 2026-08-03. https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/ (verified: primary)
  2. [2] OWASP Top 10 for LLM Applications 2026, canonical Markdown source and Appendix A: Related Framework Mappings (final list and entry texts in 2026/final; Appendix A maps each entry to the Agentic Top 10 and to CSA AICM v1.1 domains; the repository README gives the release date as 4 Aug 2026). OWASP GenAI Security Project (GitHub). 2026-08. https://github.com/GenAI-Security-Project/GenAI-LLM-Top10/blob/main/2026/final/Appendix_A_Related_Framework_Mappings.md (verified: primary)
  3. [3] OWASP Top 10 for LLM Applications 2025 (the previous edition, LLM01:2025 to LLM10:2025, used for the "formerly" ids). OWASP GenAI Security Project. 2025. https://genai.owasp.org/llm-top-10/ (verified: primary)
  4. [4] OWASP Top 10 for Agentic Applications for 2026 (ASI01 Agent Goal Hijack to ASI10 Rogue Agents). OWASP GenAI Security Project. 2025-12-09. https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/ (verified: primary)
  5. [5] MITRE ATLAS data, release v2026.09 (16 tactics, 120 techniques, 88 sub-techniques, 40 mitigations; technique names and technique-to-mitigation links read from dist/v6/ATLAS-2026.09.yaml). MITRE. 2026-09-15. https://github.com/mitre-atlas/atlas-data/releases/tag/v2026.09 (verified: primary)
  6. [6] NIST AI 100-2 E2025, Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations (predictive and generative AI attack taxonomies with NISTAML identifiers). NIST. 2025-03-24. https://csrc.nist.gov/pubs/ai/100/2/e2025/final (verified: primary)
  7. [7] NIST SP 800-218A, Secure Software Development Practices for Generative AI and Dual-Use Foundation Models: An SSDF Community Profile (AI-specific tasks added to SSDF 1.1 (e.g. PO.5.3, PS.1.3, PW.3.1 to PW.3.3) and AI-specific recommendations on existing tasks (e.g. PW.1.1, RV.1.1)). NIST. 2024-07. https://csrc.nist.gov/pubs/sp/800/218/a/final (verified: primary)
  8. [8] SP 800-53 Control Overlays for Securing AI Systems (COSAiS) (five proposed use cases; concept paper 14 Aug 2025; annotated outline for predictive AI 8 Jan 2026; no overlay published in final form on the project page as of 2026-09-24). NIST. 2026-01-08. https://csrc.nist.gov/projects/cosais (verified: primary)
  9. [9] Regulation (EU) 2024/1689 (AI Act) (Art. 15(5): resilience against attempts to alter use, outputs or performance, including data poisoning, model poisoning, adversarial examples or model evasion, confidentiality attacks and model flaws). Publications Office of the EU (EUR-Lex). 2024-07-12. https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng (verified: primary)
  10. [10] ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023. https://www.iso.org/standard/81230.html (verified: secondary)
  11. [11] AI Controls Matrix v1.1 (247 control objectives across 18 security domains; released 22 Jun 2026). Cloud Security Alliance. 2026-06-22. https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1 (verified: primary)
  12. [12] Inspect Evals (community evaluations for the Inspect framework, e.g. agentdojo, agent_threat_bench, strong_reject, cyberseceval_2). UK AI Security Institute and contributors (GitHub). 2026. https://github.com/UKGovernmentBEIS/inspect_evals (verified: primary)
  13. [13] promptfoo red-team plugins (plugin ids such as indirect-prompt-injection, prompt-extraction, rag-poisoning, agentic:memory-poisoning). promptfoo. 2026. https://www.promptfoo.dev/docs/red-team/plugins/ (verified: primary)
  14. [14] garak, LLM vulnerability scanner, release v0.17.0 (probe modules such as promptinject, latentinjection, sysprompt_extraction, leakreplay, packagehallucination). NVIDIA (GitHub). 2026-09-09. https://github.com/NVIDIA/garak (verified: primary)