Risk
Incomplete Threat Modeling for AI Systems
Description
AI threat models are absent, generic, or fail to capture the unique architectures, data flows, and attack surfaces of AI systems - leading to design-phase blind spots and misaligned security controls
Example
An AI agent chain is deployed without identifying risks from indirect tool invocation or multi-agent task decomposition, leading to unforeseen privilege escalation
Assets Affected
AI Policy
System Prompt
Meta Prompt
Dataset / RAG
Agentic platform (no code)
Mitigation
- Apply AI-specific threat modeling methods (e.g., OWASP MAS, MITRE ATLAS)
- Refresh threat models as systems evolve
- Involve cross-functional teams in modeling exercises
Standards Mapping
- ISO 42001: A.6.2.2, A.6.2.3
- NIST AI RMF: : MAP 1.6, MEASURE 2.7