v0.11.0 · working-draft
APRF Threat Intelligence Map
Why does each APRF control exist, and what does it defend against?
Not certification
Informative threat context only. Threat and MITRE mappings explain the security rationale behind a control; they are not certification, not a guarantee of mitigation, and not a substitute for the control's evidence requirements. A mapping means "this control reduces exposure to this technique", not "this control fully prevents this technique".
- Checks
- 178
- Threats
- 29
- ATLAS
- 79
- ATT&CK
- 27
Browse by threat
Closed vocabulary from the threat map. Each threat lists Checks that reduce exposure to it.
Agent Hijacking
10 checksBias and Discrimination
8 checksConfiguration Drift
22 checksData and Model Poisoning
17 checksData Exfiltration
30 checksDenial of Service
39 checksDenial of Wallet
19 checksExcessive Agency
31 checksHallucinated Actions
16 checksHarmful Content Generation
25 checksIdentity Spoofing
11 checksInsider Misuse
17 checksJailbreak
6 checksMemory Poisoning
8 checksMisinformation
36 checksModel Theft
2 checksPrivilege Escalation
26 checksPrompt Injection
38 checksRepudiation
23 checksSecret Leakage
18 checksSensitive Information Disclosure
23 checksShadow Agents
10 checksSupply Chain Compromise
23 checksSystem Prompt Leakage
3 checksTool Abuse
23 checksUnauthorized Memory Access
9 checksUnauthorized Tool Use
13 checksUnsafe Code Execution
9 checksVector and Embedding Weaknesses
2 checks
Browse by MITRE technique
ATLAS and ATT&CK technique IDs linked from Checks. Empty ATT&CK/ATLAS on a Check means the control is governance/assurance-oriented.
ATLAS AML.T0010AI Supply Chain Compromise
9 checksATLAS AML.T0010.005AI Agent Tool
3 checksATLAS AML.T0011User Execution
1 checkATLAS AML.T0011.002Poisoned AI Agent Tool
2 checksATLAS AML.T0012Valid Accounts
6 checksATLAS AML.T0018Manipulate AI Model
1 checkATLAS AML.T0018.002Embed Malware
2 checksATLAS AML.T0019Publish Poisoned Datasets
1 checkATLAS AML.T0020Poison Training Data
2 checksATLAS AML.T0024Exfiltration via AI Inference API
5 checksATLAS AML.T0024.002Extract AI Model
1 checkATLAS AML.T0025Exfiltration via Cyber Means
5 checksATLAS AML.T0029Denial of AI Service
10 checksATLAS AML.T0031Erode AI Model Integrity
3 checksATLAS AML.T0034Cost Harvesting
6 checksATLAS AML.T0034.000Excessive Queries
4 checksATLAS AML.T0034.001Resource-Intensive Queries
6 checksATLAS AML.T0034.002Agentic Resource Consumption
7 checksATLAS AML.T0035AI Artifact Collection
1 checkATLAS AML.T0036Data from Information Repositories
2 checksATLAS AML.T0037Data from Local System
3 checksATLAS AML.T0040AI Model Inference API Access
2 checksATLAS AML.T0043Craft Adversarial Data
3 checksATLAS AML.T0044Full AI Model Access
1 checkATLAS AML.T0046Spamming AI System with Chaff Data
3 checksATLAS AML.T0048External Harms
4 checksATLAS AML.T0048.003User Harm
2 checksATLAS AML.T0049Exploit Public-Facing Application
3 checksATLAS AML.T0050Command and Scripting Interpreter
4 checksATLAS AML.T0051LLM Prompt Injection
11 checksATLAS AML.T0051.000Direct
1 checkATLAS AML.T0051.001Indirect
8 checksATLAS AML.T0051.002Triggered
1 checkATLAS AML.T0053AI Agent Tool Invocation
13 checksATLAS AML.T0054LLM Jailbreak
7 checksATLAS AML.T0055Unsecured Credentials
11 checksATLAS AML.T0056Extract LLM System Prompt
3 checksATLAS AML.T0057LLM Data Leakage
8 checksATLAS AML.T0058Publish Poisoned Models
5 checksATLAS AML.T0059Erode Dataset Integrity
3 checksATLAS AML.T0064Gather RAG-Indexed Targets
2 checksATLAS AML.T0066Retrieval Content Crafting
2 checksATLAS AML.T0067LLM Trusted Output Components Manipulation
2 checksATLAS AML.T0067.000Citations
1 checkATLAS AML.T0068LLM Prompt Obfuscation
3 checksATLAS AML.T0069Discover LLM System Information
1 checkATLAS AML.T0069.002System Prompt
2 checksATLAS AML.T0070RAG Poisoning
6 checksATLAS AML.T0071False RAG Entry Injection
3 checksATLAS AML.T0072Reverse Shell
3 checksATLAS AML.T0073Impersonation
2 checksATLAS AML.T0074Masquerading
1 checkATLAS AML.T0076Corrupt AI Model
5 checksATLAS AML.T0077LLM Response Rendering
1 checkATLAS AML.T0080AI Agent Context Poisoning
4 checksATLAS AML.T0080.000Memory
6 checksATLAS AML.T0080.001Thread
2 checksATLAS AML.T0081Modify AI Agent Configuration
2 checksATLAS AML.T0082RAG Credential Harvesting
2 checksATLAS AML.T0083Credentials from AI Agent Configuration
2 checksATLAS AML.T0085Data from AI Services
4 checksATLAS AML.T0085.000RAG Databases
5 checksATLAS AML.T0086Exfiltration via AI Agent Tool Invocation
12 checksATLAS AML.T0091Use Alternate Authentication Material
2 checksATLAS AML.T0091.000Application Access Token
1 checkATLAS AML.T0092Manipulate User LLM Chat History
2 checksATLAS AML.T0094Delay Execution of LLM Instructions
1 checkATLAS AML.T0096AI Service API
1 checkATLAS AML.T0098AI Agent Tool Credential Harvesting
1 checkATLAS AML.T0099AI Agent Tool Data Poisoning
2 checksATLAS AML.T0101Data Destruction via AI Agent Tool Invocation
7 checksATLAS AML.T0102Generate Malicious Commands
4 checksATLAS AML.T0103Deploy AI Agent
1 checkATLAS AML.T0104Publish Poisoned AI Agent Tool
2 checksATLAS AML.T0105Escape to Host
1 checkATLAS AML.T0106Exploitation for Credential Access
1 checkATLAS AML.T0107Exploitation for Defense Evasion
1 checkATLAS AML.T0109AI Supply Chain Rug Pull
4 checksATLAS AML.T0110AI Agent Tool Poisoning
3 checksATT&CK T1041Exfiltration Over C2 Channel
4 checksATT&CK T1059Command and Scripting Interpreter
3 checksATT&CK T1068Exploitation for Privilege Escalation
2 checksATT&CK T1070Indicator Removal
1 checkATT&CK T1071Application Layer Protocol
1 checkATT&CK T1078Valid Accounts
12 checksATT&CK T1078.004Cloud Accounts
1 checkATT&CK T1090Proxy
1 checkATT&CK T1098Account Manipulation
3 checksATT&CK T1190Exploit Public-Facing Application
3 checksATT&CK T1195Supply Chain Compromise
10 checksATT&CK T1195.002Compromise Software Supply Chain
4 checksATT&CK T1213Data from Information Repositories
4 checksATT&CK T1485Data Destruction
4 checksATT&CK T1486Data Encrypted for Impact
1 checkATT&CK T1499Endpoint Denial of Service
2 checksATT&CK T1530Data from Cloud Storage
2 checksATT&CK T1548Abuse Elevation Control Mechanism
2 checksATT&CK T1550Use Alternate Authentication Material
2 checksATT&CK T1550.001Application Access Token
1 checkATT&CK T1552Unsecured Credentials
9 checksATT&CK T1552.001Credentials In Files
6 checksATT&CK T1556Modify Authentication Process
1 checkATT&CK T1565Data Manipulation
1 checkATT&CK T1567Exfiltration Over Web Service
4 checksATT&CK T1611Escape to Host
1 checkATT&CK T1685Disable or Modify Tools
1 check
Browse by Check
Full index of Checks with security intent and threat chips.
Ensure every production agent has an approved, documented operating boundary so no agent runs unaccounted for.
Shadow AgentsExcessive AgencyUnauthorized Tool UsePrevent autonomous agents from executing beyond approved operational limits.
Excessive AgencyDenial of WalletTool AbuseDenial of ServiceGive operators a reliable means to halt agent execution when it behaves unsafely or is under attack.
Agent HijackingExcessive AgencyTool AbuseDenial of WalletEnsure agent-to-agent handoffs authenticate the peer and carry only scoped, least-privilege capabilities.
Identity SpoofingAgent HijackingPrivilege EscalationUnauthorized Tool UseDetect conflicting or policy-violating agent goals before a plan is allowed to execute.
Excessive AgencyHallucinated ActionsPrompt InjectionValidate new agent behaviour in an isolated environment before it can act on production systems.
Excessive AgencyUnsafe Code ExecutionHallucinated ActionsTool AbuseEstablish accountable ownership for every production agent across the teams that operate it.
Shadow AgentsExcessive AgencyEnsure no production AI endpoint serves an unauthenticated caller.
Identity SpoofingDenial of WalletModel TheftData ExfiltrationEnsure every service-to-service and MCP connection proves a strong machine identity rather than a shared static secret.
Identity SpoofingPrivilege EscalationUnauthorized Tool UseSupply Chain CompromisePrevent takeover of AI control planes through compromised administrator credentials.
Identity SpoofingPrivilege EscalationInsider MisuseSupply Chain CompromisePreserve the end user's identity through agent and tool hops so downstream authorization is evaluated against the real principal.
Privilege EscalationIdentity SpoofingUnauthorized Tool UseData ExfiltrationLimit the useful lifetime of agent and tool credentials so leaked material expires quickly.
Secret LeakageIdentity SpoofingPrivilege EscalationData ExfiltrationEnsure self-hosted inference runtimes authenticate as attested workloads rather than with embedded static secrets.
Identity SpoofingSecret LeakagePrivilege EscalationEnsure every AI feature, tool call, and retrieval is authorized server-side and never by model output alone.
Privilege EscalationUnauthorized Tool UseData ExfiltrationPrompt InjectionExcessive AgencyPrevent one tenant's data, memory, or retrieval context from reaching another tenant.
Unauthorized Memory AccessData ExfiltrationSensitive Information DisclosurePrivilege EscalationConstrain what an agent identity is permitted to do so that a compromised agent has limited reach.
Privilege EscalationExcessive AgencyAgent HijackingData ExfiltrationTool AbuseEnforce attribute-based restrictions so sensitive document classes cannot enter retrieval or context without authorization.
Data ExfiltrationSensitive Information DisclosureUnauthorized Memory AccessPrompt InjectionExpress tool and model access rules as reviewable, testable code rather than ad hoc configuration.
Privilege EscalationUnauthorized Tool UseExcessive AgencyConfiguration DriftDetect and remove privilege that high-privilege agent identities accumulate over time.
Privilege EscalationExcessive AgencyInsider MisuseShadow AgentsGuarantee that a known-good prompt and model state can be restored after a harmful or compromised change.
Configuration DriftData and Model PoisoningDenial of ServiceRepudiationEnsure the responder on shift can actually reverse a harmful AI change under incident conditions.
Denial of ServiceHarmful Content GenerationConfiguration DriftVerify that the rollback capability actually works before it is needed in an incident.
Denial of ServiceConfiguration DriftReduce time-to-recovery by making rollback a single low-error operation.
Denial of ServiceHarmful Content GenerationConfiguration DriftAllow new agent behaviour to be disabled instantly without a redeploy.
Excessive AgencyTool AbuseHarmful Content GenerationDenial of WalletAutomatically revert AI releases that degrade quality or safety beyond agreed thresholds.
Harmful Content GenerationMisinformationDenial of ServiceEnsure the legal and regulatory obligations that apply to production AI are identified and owned.
RepudiationInsider MisuseTie each in-scope AI obligation to the concrete evidence artifact that demonstrates it.
RepudiationPreserve an immutable record of AI control-plane changes for detection and investigation.
RepudiationInsider MisusePrivilege EscalationTest controls on a cadence and record the exceptions that testing reveals.
RepudiationConfiguration DriftGive customers an accurate, published account of the AI controls in place.
RepudiationObtain independent verification of control effectiveness for the highest-capability systems.
RepudiationInsider MisuseCap the financial and capacity impact of abusive or runaway AI usage.
Denial of WalletDenial of ServiceExcessive AgencyDetect abnormal AI spend early enough to intervene.
Denial of WalletDenial of ServicePrevent retry and loop logic from amplifying a single request into unbounded cost.
Denial of WalletDenial of ServiceExcessive AgencyReduce the cost and capacity impact of repeated identical requests.
Denial of WalletDenial of ServiceReduce unit cost without silently degrading quality on low-risk tasks.
Denial of WalletMisinformationKeep AI unit economics under periodic review so structural cost drift is caught.
Denial of WalletBound context assembly so oversized or attacker-padded input cannot displace instructions or exhaust resources.
Prompt InjectionDenial of ServiceDenial of WalletEnsure content entering the context is attributed to a source and authorized for the requesting principal.
Prompt InjectionData ExfiltrationUnauthorized Memory AccessSensitive Information DisclosurePrevent secrets and regulated data from entering model context without an explicit approved policy.
Secret LeakageSensitive Information DisclosureData ExfiltrationDetect context saturation that degrades answer quality or signals abuse.
Denial of ServiceDenial of WalletPrompt InjectionEnsure compaction and summarization do not silently discard facts that decisions depend on.
MisinformationHallucinated ActionsMake untrusted content structurally distinguishable from system instructions.
Prompt InjectionAgent HijackingEnsure prompts, models, and tools reach production only through a reviewed promotion path.
Supply Chain CompromiseConfiguration DriftData and Model PoisoningInsider MisuseMaintain an attributable record of every production AI artifact change.
RepudiationInsider MisuseConfiguration DriftSupply Chain CompromiseMake AI infrastructure and configuration reviewable and reproducible rather than manually mutated.
Configuration DriftPrivilege EscalationInsider MisuseLimit the population exposed to a new AI change until it is proven healthy.
Harmful Content GenerationMisinformationDenial of ServiceEnsure the models and tools validated in test are the ones actually serving production traffic.
Configuration DriftSupply Chain CompromiseUnauthorized Tool UsePrevent inconsistent or partially migrated retrieval indexes from serving production traffic.
Vector and Embedding WeaknessesMisinformationDenial of ServiceEstablish accountable ownership and version control over the corpora that ground production answers.
Data and Model PoisoningMemory PoisoningMisinformationEnsure data used for evaluation and fine-tuning comes from known, vetted sources.
Data and Model PoisoningSupply Chain CompromiseMisinformationPrevent unvetted feedback or memory from being promoted into content that shapes future answers.
Memory PoisoningData and Model PoisoningMisinformationDetect stale or incomplete corpora before they degrade grounded answers.
MisinformationData and Model PoisoningDetect divergence between offline and online pipelines that silently degrades results.
Vector and Embedding WeaknessesMisinformationConfiguration DriftDocument dataset purpose, source, and PII handling so downstream reuse is an informed decision.
Data and Model PoisoningSensitive Information DisclosureMake the controlled route to production the easiest route, so teams do not build around it.
Configuration DriftShadow AgentsInsider MisuseLet builders detect control failures before merge rather than at release.
Secret LeakageIdentity SpoofingConfiguration DriftMake safe configuration the starting point for new agent, RAG, and MCP services.
Configuration DriftPrompt InjectionSecret LeakageLet builders run evaluations before opening a pull request.
MisinformationHallucinated ActionsMeasure whether the paved road is actually being used.
Configuration DriftShadow AgentsGive the AI platform a named owner and a support channel so problems have somewhere to go.
Shadow AgentsDetect quality and safety regressions in critical journeys before they reach users.
MisinformationHallucinated ActionsHarmful Content GenerationEnsure releases cannot proceed when quality or safety metrics fall below agreed minimums.
MisinformationHarmful Content GenerationHallucinated ActionsObserve real production outcomes, including safety refusals, rather than relying on pre-release testing alone.
Harmful Content GenerationJailbreakPrompt InjectionMisinformationCompare a candidate AI change against production behaviour before it serves users.
MisinformationHarmful Content GenerationDenial of ServiceEnsure adversarial robustness is measured on its own and not averaged away by aggregate quality scores.
Prompt InjectionJailbreakMisinformationApply human judgement to outputs on a cadence, where automated metrics cannot recognize the harm.
MisinformationHarmful Content GenerationBias and DiscriminationEnsure grounded answers carry verifiable source attribution so claims can be checked.
MisinformationHallucinated ActionsPrompt InjectionMake it possible to reconstruct how a specific production AI outcome was reached.
RepudiationPrompt InjectionHallucinated ActionsPrevent explanation and rationale surfaces from becoming a disclosure channel.
Sensitive Information DisclosureSystem Prompt LeakageSecret LeakageData ExfiltrationGive users an intelligible reason for material automated decisions that affect them.
RepudiationBias and DiscriminationMisinformationMap formal explainability obligations to the regulated features they apply to.
RepudiationBias and DiscriminationMake the behavioural effect of a model or prompt change reviewable rather than inferred.
Configuration DriftMisinformationRequire a human decision before an AI system performs a high-impact or irreversible action.
Excessive AgencyHallucinated ActionsPrompt InjectionAgent HijackingTool AbuseRecord who approved each high-impact AI action, on what evidence, and with what outcome.
RepudiationInsider MisuseExcessive AgencyEnsure no alternate agent, API, or tool path can perform a gated action without approval.
Privilege EscalationExcessive AgencyUnauthorized Tool UseTool AbuseRequire two independent human authorizations before irreversible high-severity actions.
Insider MisuseExcessive AgencyHallucinated ActionsAgent HijackingGive approvers the context needed to make approval a real decision rather than a reflex.
Excessive AgencyHallucinated ActionsPrompt InjectionTool AbuseKeep approval queues fast enough that teams do not route around the gate.
Excessive AgencyInsider MisuseEnsure responders have prepared procedures for AI-specific incident classes.
Prompt InjectionData ExfiltrationHarmful Content GenerationAgent HijackingDenial of ServiceEnsure on-call responders can actually stop AI activity during an incident.
Agent HijackingExcessive AgencyTool AbuseData ExfiltrationDenial of WalletPage responders on safety and quality signals, not only on infrastructure health.
Harmful Content GenerationJailbreakMisinformationConvert incident learning into owned, tracked control improvements.
RepudiationDefine in advance when an AI-related event requires customer notification.
RepudiationSensitive Information DisclosureRehearse AI-specific incident response before a real event tests it.
Prompt InjectionData ExfiltrationAgent HijackingEliminate unauthenticated public exposure of AI data stores and control planes.
Data ExfiltrationSensitive Information DisclosurePrivilege EscalationModel TheftBound the exposure window for known vulnerabilities in AI runtime environments.
Privilege EscalationUnsafe Code ExecutionSupply Chain CompromiseRestrict outbound reachability from agent and tool runtimes to an approved set of destinations.
Data ExfiltrationAgent HijackingTool AbuseSupply Chain CompromisePrevent one tenant on shared AI accelerators from reading or starving another.
Data ExfiltrationUnauthorized Memory AccessDenial of ServiceEnsure only cryptographically verified AI artifacts are allowed to run in production.
Supply Chain CompromiseData and Model PoisoningUnsafe Code ExecutionCatch insecure infrastructure defaults before they are deployed.
Configuration DriftPrivilege EscalationData ExfiltrationPrevent AI memory from being read or influenced across tenant and user boundaries.
Unauthorized Memory AccessData ExfiltrationMemory PoisoningSensitive Information DisclosureEnsure AI memory is retained only as long as policy allows and can actually be deleted.
Sensitive Information DisclosureUnauthorized Memory AccessRepudiationEnsure only authorized principals and validated content can write to durable AI memory.
Memory PoisoningData and Model PoisoningPrompt InjectionMisinformationMake tampering with critical memory records detectable.
Memory PoisoningUnauthorized Memory AccessRepudiationVerify that memory write and retrieval controls actually resist poisoning attempts.
Memory PoisoningPrompt InjectionMisinformationPrevent transient session content from becoming durable knowledge without an explicit promotion decision.
Memory PoisoningUnauthorized Memory AccessMisinformationEnsure production behaviour comes from an explicitly chosen, evaluated model version.
Supply Chain CompromiseConfiguration DriftMisinformationRequire evaluation evidence before any model change is promoted to production.
MisinformationHarmful Content GenerationData and Model PoisoningManage model and embedding deprecation before a provider withdrawal forces it.
Configuration DriftDenial of ServiceGrant each workload only the model capabilities it actually needs.
Unsafe Code ExecutionExcessive AgencyPrompt InjectionTool AbuseReview the license and provenance of open-weight and fine-tuned models before adoption.
Supply Chain CompromiseData and Model PoisoningMaintain an accurate inventory of the models running in production and their intended use.
Shadow AgentsConfiguration DriftSensitive Information DisclosureMake the full AI execution path observable end to end for detection and investigation.
RepudiationPrompt InjectionTool AbuseData ExfiltrationPrevent observability pipelines from becoming a secondary store of sensitive data.
Secret LeakageSensitive Information DisclosureData ExfiltrationEnable safe reproduction of failed AI interactions without exposing production data.
Sensitive Information DisclosurePrompt InjectionTurn observed production failures into evaluation cases.
MisinformationHallucinated ActionsPresent AI latency, error, and quality burn against SLOs in one place.
Denial of ServiceMisinformationAttribute AI consumption precisely enough to detect abuse and runaway usage.
Denial of WalletExcessive AgencyEstablish the organization's binding boundary for acceptable and prohibited AI use.
Insider MisuseHarmful Content GenerationShadow AgentsKeep AI risk posture visible to the leadership that can fund and mandate remediation.
Shadow AgentsAssign named owners to the APRF domains that matter for each production AI system.
Shadow AgentsRepudiationFeed incidents and evaluation failures into a tracked improvement backlog.
RepudiationRecord accepted control gaps with an owner and an expiry rather than leaving them implicit.
RepudiationInsider MisuseIndependently sample APRF evidence to confirm that claimed controls are real.
RepudiationInsider MisuseDefine the availability and latency commitment for critical AI user journeys.
Denial of ServiceExpose latency, error, and AI quality metrics so degradation is measurable.
Denial of ServiceMisinformationAlert when SLO burn indicates the system is degrading beyond agreed limits.
Denial of ServiceDenial of WalletUse error budgets to slow release velocity when AI reliability is degrading.
Denial of ServiceValidate that the system withstands deliberately expensive prompts and agent loops.
Denial of ServiceDenial of WalletExcessive AgencyMeasure streaming-specific latency so perceived responsiveness is not invisible to SLOs.
Denial of ServicePresent AI operational metrics in near real time so degradation is seen as it happens.
Denial of ServiceKnow which data classes reach models so sensitive classes can be handled under explicit rules.
Sensitive Information DisclosureData ExfiltrationSecret LeakageEnsure data subject deletion and export actually reach AI memory, traces, and logs.
Sensitive Information DisclosureUnauthorized Memory AccessRepudiationPrevent regulated workloads from being processed outside their permitted jurisdiction.
Sensitive Information DisclosureData ExfiltrationRemove or tokenize high-sensitivity fields before they reach a model.
Sensitive Information DisclosureData ExfiltrationSecret LeakageEnsure third-party model provider terms do not permit training on or over-retaining production data.
Sensitive Information DisclosureAssess privacy and rights impact before a major AI feature reaches production.
Sensitive Information DisclosureBias and DiscriminationMake the exact prompt serving production identifiable, attributable, and immutable.
Configuration DriftRepudiationPrompt InjectionEnsure prompt changes are reviewed and backed by evaluation evidence before release.
Harmful Content GenerationPrompt InjectionMisinformationInsider MisuseAllow rollback to a prior prompt version without redeploying unrelated services.
Harmful Content GenerationDenial of ServiceConfiguration DriftKeep secrets and personal data out of prompt source and templates.
Secret LeakageSystem Prompt LeakageSensitive Information DisclosurePrompt InjectionCatch injection-prone and unsafe prompt constructs before they reach production.
Prompt InjectionSecret LeakageSystem Prompt LeakageMeasure the real impact of high-traffic prompt changes before full rollout.
Harmful Content GenerationMisinformationPrevent a slow or failing dependency from exhausting capacity or amplifying cost.
Denial of ServiceDenial of WalletExcessive AgencyKeep critical user journeys functional when the AI path is unavailable.
Denial of ServicePrevent tool-using workflows from reporting success when steps have silently failed.
Hallucinated ActionsMisinformationExcessive AgencyEnsure the artifacts required to restore AI service survive a destructive event.
Denial of ServiceData and Model PoisoningSupply Chain CompromiseSet explicit recovery time and recovery point objectives for business-critical AI services.
Denial of ServiceStop a failing AI provider from cascading into total service failure.
Denial of ServiceRemove single-provider dependency for critical AI journeys without lowering the quality bar.
Denial of ServiceDocument how critical AI-dependent business processes continue when AI is unavailable.
Denial of ServiceRehearse continuity, including full provider loss, before it is tested by a real outage.
Denial of ServiceDeliberately exercise AI dependency failure modes in production-like conditions.
Denial of ServiceKeep standby inference capacity ready where self-hosted models are business-critical.
Denial of ServiceBack multi-provider continuity with contractual commitments, not just technical routing.
Denial of ServiceSupply Chain CompromiseDefine what constitutes unsafe output and behaviour for this specific product domain.
Harmful Content GenerationMisinformationBias and DiscriminationBlock releases that fail the organization's stated safety bar.
Harmful Content GenerationJailbreakMisinformationBias and DiscriminationEnsure users know when they are interacting with an AI system.
MisinformationIdentity SpoofingMeasure disparate outcomes on high-stakes automated decision paths.
Bias and DiscriminationHarmful Content GenerationApply human judgement to safety edge cases that automated evaluation classifies poorly.
Harmful Content GenerationBias and DiscriminationMisinformationTest whether safety controls hold end to end, from jailbreak attempt through to real-world harm.
JailbreakHarmful Content GenerationPrompt InjectionEnsure production AI artifacts come from a verified source and have not been tampered with.
Supply Chain CompromiseData and Model PoisoningUnsafe Code ExecutionEnsure every external tool, MCP server, and plugin in production is known, pinned, and reviewed.
Supply Chain CompromiseTool AbuseUnauthorized Tool UsePrompt InjectionBlock deployment of AI artifacts carrying known exploitable vulnerabilities.
Supply Chain CompromiseUnsafe Code ExecutionPrivilege EscalationEnforce at the deployment boundary that only approved, signed AI artifacts can run.
Supply Chain CompromiseData and Model PoisoningInsider MisuseVerify artifact signatures against build provenance at deploy time.
Supply Chain CompromiseData and Model PoisoningRecord the composition of each production model pin so affected deployments can be found quickly.
Supply Chain CompromiseData and Model PoisoningPrevent untrusted model input from being treated as an authorization decision for privileged actions.
Prompt InjectionPrivilege EscalationExcessive AgencyUnauthorized Tool UseEnsure model output cannot cause side effects until it has been validated against an explicit schema or policy.
Prompt InjectionUnsafe Code ExecutionHallucinated ActionsTool AbuseHarmful Content GenerationPrevent releases that regress the system's resistance to jailbreak, abuse, and injection.
Prompt InjectionJailbreakHarmful Content GenerationData ExfiltrationPrevent the model and agent path from becoming an unrestricted proxy into internal systems and networks.
Data ExfiltrationPrivilege EscalationPrompt InjectionTool AbuseValidate defences against multi-turn and retrieval-borne indirect prompt injection.
Prompt InjectionMemory PoisoningData ExfiltrationTool AbusePrevent malicious or unsafe multimodal payloads from reaching the model or downstream systems.
Prompt InjectionHarmful Content GenerationUnsafe Code ExecutionSupply Chain CompromiseDetect attempts to exfiltrate sensitive data through AI request and response paths.
Data ExfiltrationSensitive Information DisclosureSecret LeakagePrompt InjectionKeep production secrets out of prompts, source control, and notebooks.
Secret LeakagePrivilege EscalationIdentity SpoofingData ExfiltrationPrevent secrets from being persisted into logs and traces.
Secret LeakageSensitive Information DisclosurePrivilege EscalationEnsure AI credentials are narrowly scoped, rotatable, and never shipped to clients.
Secret LeakageDenial of WalletPrivilege EscalationIdentity SpoofingDetect committed secrets before they reach a shared repository.
Secret LeakageSupply Chain CompromiseConstrain where a leaked runtime credential can actually be used from.
Secret LeakageData ExfiltrationPrivilege EscalationPrevent secrets and sensitive data from being baked into models or published corpora.
Secret LeakageSensitive Information DisclosureData and Model PoisoningEnsure tool execution authority comes from server-side policy, never from model output.
Prompt InjectionUnauthorized Tool UsePrivilege EscalationExcessive AgencyTool AbuseRestrict each agent to a fixed, approved set of tools it cannot expand at runtime.
Unauthorized Tool UseTool AbuseExcessive AgencySupply Chain CompromiseRequire an additional gate before high-impact tools are permitted to execute.
Excessive AgencyTool AbuseHallucinated ActionsPrompt InjectionPrevent unvalidated model-generated arguments from reaching an executor.
Unsafe Code ExecutionPrompt InjectionTool AbusePrivilege EscalationEnsure tool catalog definitions are authentic and unchanged since they were reviewed.
Supply Chain CompromisePrompt InjectionTool AbuseUnauthorized Tool UseLet destructive tool behaviour be validated without producing irreversible effects.
Excessive AgencyHallucinated ActionsTool AbuseBound how much damage a single agent or tool can do within a given window.
Tool AbuseExcessive AgencyData ExfiltrationDenial of WalletDenial of Service
Sources
- MITRE ATLAS 5.6.0All AML.T identifiers were validated against the published ATLAS distribution.
- MITRE ATT&CK for Enterprise 19.2All T identifiers were validated against the published ATT&CK STIX bundle.
- OWASP Top 10 for LLM Applications (2025)Source for extended threat names not present in the core vocabulary.
Machine-readable: /aprf/threat-map.json. Normative Checks remain in /aprf/spec/.