
21 named threats catalogued across both directions of the AI security threat model. The framework morphs by lens; threats can be selected to focus the view on a specific incident.
Map catalogued threats and controls to the CSF function you already report against. Function first.
Start here if the board or a regulator is your audience.
Open Crosswalk →See who acts, in what order, for a selected threat. Threat first, with delegation fallback for lean teams.
Start here if you run the team that responds.
Open Swimlane →Evaluate what a capability stack changes across the six functions.
Start here if you are choosing or defending a security stack.
Open Stack Lab →Each lens morphs the diagram layout · Dimensions filter the threat population without changing the shape
Maintains a structured, evidence-based view of how AI can be used as an attack tool and how AI systems themselves can be attacked, using existing public taxonomies.