Crosswalk view // MITRE ATLAS v2026.05
NIST CSF 2.0 for agentic AI threats
The board-facing entry into the six-domain framework. Pick the CSF function your programme already reports against, and see which of the 21 validated threats, mitigation controls, and Singapore anchors (IMDA MGF, MAS AIRG, CSA Singapore) land there. Govern wraps the five operational functions, it is not a peer.
Maps to domains
D01 GovernAI augmentation
Human-gated
Governance stays human-owned. AI assists inventory and reporting only.
NIST AI RMF Govern function90-day sequence
Days 1 to 30Register AI-orchestrated intrusion and AI-system compromise as named risks. Nominate a named owner per domain.
Singapore anchor
IMDA MGF dimension 1 (bounding risk); MAS AIRG (AI inventory, senior-management oversight).
Threats that land here
Anchor incident: 80 to 90 percent autonomous espionage
First attributed nation-state LLM use
Mitigation controls
M-A2-02DConsume vendor abuse-detection threat reports (Anthropic, OpenAI, GTIG)NIST AI RMF Govern
M-A2-03DISAC and threat-intelligence sharing participationNIST AI RMF Govern
M-A4-04RVendor threat-intel sharing protocols (direct channels with AI providers)NIST AI RMF Govern
Next action // Days 1 to 30
Register AI-orchestrated intrusion and AI-system compromise as named risks. Nominate a named owner per domain.
AI-augmentableHuman-gated / mixedNot yet mature / open gapArrow keys to move between functions
Steady-state ownership //Steady-state ownership (who owns each domain year-round) lives in the framework document, Section 2.4.