Pidoku

Frameworks and Maps

Foundations 45 min Difficulty 2/5 Lesson 03 of 03

Prerequisites Threat Modeling an AI System

The idea in one minute#

Five public frameworks cover AI security, and they answer different questions. The OWASP Top 10 for LLM Applications and the OWASP Top 10 for Agentic Applications say what goes wrong most often. MITRE ATLAS says how attackers actually do it, technique by technique. NIST’s AI Risk Management Framework and its control overlays say how to run a programme. The EU AI Act says what the law requires. Use the first two as checklists, the third for red teaming and detection, the fourth for governance, and the fifth for obligations. None replaces a threat model of your own system.

Everything dated here was checked on 4 October 2026.

A picture#

flowchart TB
  TM[":i-list-checks: <b>Your threat model</b><br/><small>specific to your system</small>"]
  subgraph WHAT["What goes wrong"]
    direction LR
    O1[":owasp: <b>OWASP LLM Top 10</b><br/><small>2026 edition</small>"]
    O2[":owasp: <b>OWASP Agentic Top 10</b><br/><small>ASI01 - ASI10</small>"]
  end
  subgraph HOW["How attackers do it"]
    direction LR
    AT[":mitre: <b>MITRE ATLAS</b><br/><small>tactics, techniques, case studies</small>"]
  end
  subgraph RUN["How to run the programme"]
    direction LR
    N1[":nist: <b>NIST AI RMF</b><br/><small>govern, map, measure, manage</small>"]
    N2[":nist: <b>COSAiS overlays</b><br/><small>SP 800-53 for AI</small>"]
    ISO[":i-scroll-text: <b>ISO/IEC 42001</b><br/><small>management system</small>"]
  end
  subgraph LAW["What is required"]
    direction LR
    EU[":i-scale: <b>EU AI Act</b>"]
  end
  O1 --> TM
  O2 --> TM
  AT --> TM
  TM --> N1
  N2 --> TM
  EU --> N1
  ISO --> N1
  class TM compute
  class O1,O2 warn
  class AT io
  class N1,N2,ISO queue
  class EU memory

How it really works#

OWASP Top 10 for LLM Applications — 2026 edition#

Published on 4 August 2026. No category was added or removed since 2025, but the ranking was rebuilt from incident data, and it shifted toward what agents made dangerous.

#RiskIn one line
1Prompt InjectionText that changes the model’s behaviour; now explicitly includes instructions hidden in images and audio
2Sensitive Information DisclosureThe system reveals private data, secrets or proprietary content
3Excessive AgencyThe model has more tools, permissions or autonomy than its task needs — up from sixth place
4Supply ChainCompromised models, datasets, packages, tools
5Data and Model PoisoningCorrupted training, fine-tuning or retrieval data
6Unbounded ConsumptionResource exhaustion, denial of wallet, model extraction by volume
7MisinformationConfident wrong output that people or systems act on
8Hidden Context ExposureLeakage of system prompts and other context the user was not meant to see — the renamed and widened “System Prompt Leakage”
9Vector and Embedding WeaknessesAttacks on retrieval: poisoned chunks, cross-tenant leaks, embedding inversion
10Improper Output HandlingModel output passed unvalidated to a browser, shell, database or API

The edition’s framing is the one this course adopts: assume the model will be fooled, and put the controls around it.

OWASP Top 10 for Agentic Applications#

Announced in December 2025 for systems where models plan, use tools, keep memory and work with other agents.

IDRiskPrimary defenceCovered in
ASI01Agent Goal HijackTreat all retrieved content as untrusted; constrain what the agent may pursuePrompt Injection
ASI02Tool Misuse and ExploitationLeast-agency tool scoping; argument validationArchitectural Defenses
ASI03Identity and Privilege AbusePer-agent identity; short-lived scoped credentialsIdentity and Authorization
ASI04Agentic Supply Chain VulnerabilitiesSigned components; AI bill of materials; provenanceMCP and Tool Security
ASI05Unexpected Code ExecutionSandboxed execution; deny-by-default egressSandboxing and Egress
ASI06Memory and Context PoisoningValidated memory writes; provenanceAgent Threats
ASI07Insecure Inter-Agent CommunicationMutual authentication; signed messagesIdentity and Authorization
ASI08Cascading FailuresBlast-radius isolation; circuit breakers; budgetsAgent Threats
ASI09Human-Agent Trust ExploitationMeaningful confirmation for sensitive actionsArchitectural Defenses
ASI10Rogue AgentsBehavioural monitoring; kill switchesMonitoring and Response

Use both lists as coverage checks: for each item, your design should name the control or state why the risk does not apply.

MITRE ATLAS#

ATLAS is to AI what ATT&CK is to enterprise networks: a matrix of adversary tactics (the goal of a step — reconnaissance, initial access, persistence, exfiltration) and the techniques that achieve each, backed by real case studies. Its 2025 and 2026 updates added a substantial set of agent-specific techniques — context poisoning, tool-invocation abuse, harvesting credentials that were ingested into a retrieval store, and others — and most of the current matrix is now relevant to agentic systems.

Where it earns its place:

  • Red teaming — a technique list is a test plan.
  • Detection engineering — each technique suggests what a log should show.
  • Incident write-ups — a shared vocabulary for what the attacker did, step by step.

NIST#

  • AI Risk Management Framework (AI RMF) organises work into four functions: Govern (policies, roles, accountability), Map (context and risks), Measure (test and monitor), Manage (prioritise and respond). It is voluntary and widely used as the backbone of an AI governance programme; a Generative AI profile adds specifics.
  • COSAiS — Control Overlays for Securing AI Systems — adapts the familiar SP 800-53 control catalogue to AI use cases, including single-agent and multi-agent systems. It is in development; the agent-specific overlays were not yet final at the time of checking.

If your organisation already runs on SP 800-53 or ISO 27001, these are how AI gets folded into the existing control set rather than treated as a separate universe. ISO/IEC 42001 plays the same role as a certifiable management-system standard.

The EU AI Act, by date#

The Act classifies systems by risk and applies obligations in stages. The schedule was amended by the “Digital Omnibus on AI”, on which the Council and Parliament reached provisional agreement in May 2026.

DateWhat applies
2 February 2025Prohibited practices (Article 5); AI-literacy duties
2 August 2025Obligations for providers of general-purpose AI models
2 August 2026Transparency duties (Article 50), including labelling of AI-generated content
2 December 2027High-risk obligations for standalone Annex III systems — deferred from August 2026 by the omnibus agreement
2 August 2028High-risk obligations for AI embedded in regulated products (Annex I) — deferred from August 2027

Formal adoption of the omnibus was still pending when this was checked; confirm the dates before relying on them, and note that a deferral is not an exemption. For engineers, the high-risk requirements read like a security and quality checklist: risk management, data governance, logging, human oversight, accuracy, robustness and cybersecurity. Compliance and Regulation maps them to controls.

Which to reach for#

You need toUse
Check a design for common gapsOWASP LLM Top 10 and Agentic Top 10
Plan a red-team exerciseMITRE ATLAS techniques
Decide what to log and alert onMITRE ATLAS, per technique
Stand up or audit an AI governance programmeNIST AI RMF; ISO/IEC 42001
Fold AI into existing security controlsCOSAiS overlays on SP 800-53
Know your legal duties in the EUThe AI Act, by risk class and date
Find what is wrong with your systemYour own threat model

Remember this#

  • OWASP lists say what goes wrong; ATLAS says how; NIST and ISO say how to manage; the AI Act says what is required.
  • In the 2026 LLM Top 10, Excessive Agency rose to third: agents are the growing risk.
  • The Agentic Top 10 (ASI01–ASI10) is the checklist for anything with tools and memory.
  • EU high-risk deadlines moved to December 2027 and August 2028; transparency duties did not move.
  • Frameworks check coverage. They do not replace a threat model.

Try it#

  1. Take the Agentic Top 10 and, for a system you know, write one line per item: the control, or why it does not apply.
  2. Pick one ATLAS technique and describe the log entry that would reveal it.
  3. Decide which AI Act risk class a product of yours would fall into, and which date applies.

Check yourself#

  1. What changed between the 2025 and 2026 OWASP LLM lists, and what does the change signal?
  2. What is ATLAS for that a Top 10 list is not?
  3. Why can no framework substitute for a system-specific threat model?

Sources#

↑↓ navigate↵ openesc close

drag to pan · scroll to zoom