PERSONAL RESEARCH / THREAT CATALOG
Elementary threats
to AI systems.
Eleven proposed AI-specific threats to complement the BSI IT-Grundschutz compendium.
Open an entry to read more. Keep several open to compare them.
G AI.01Compromise of Source Data or ModelsManipulated data or model components can change an AI system’s behaviour without being detected.
Poisoning can affect training data, fine-tuning data or retrieved knowledge at several points in the supply chain. Pre-trained models can also contain hidden backdoors or altered parameters that take effect after adoption.
LINK TO THIS THREATG AI.02Prompt InjectionsCrafted inputs can redirect an AI system or cause it to disregard its intended instructions.
Malicious instructions may arrive directly or be hidden in external material the system processes. This report also includes adversarial input changes that cause other AI models to misclassify data.
LINK TO THIS THREATG AI.03Erroneous or Unreliable OutputsAI results can appear credible while containing errors or becoming unreliable under changed operating conditions.
Hallucinated references, errors in generated code and reduced accuracy on changed inputs can pass unnoticed. Faulty generalisation, model drift or limited robustness can make apparently plausible results unreliable.
LINK TO THIS THREATG AI.04Inference of Sensitive InformationModel responses can expose confidential information from training data, system configuration or user input.
Queries can reveal training records, whether particular data was used in training, or confidential system instructions. Memorised information and insufficient separation between users can also lead to disclosure.
LINK TO THIS THREATG AI.05Biased or Discriminatory ResultsAI decisions can systematically disadvantage particular groups of people.
Unbalanced or flawed source data can carry existing prejudices into results, while model design can amplify them. This can produce unequal treatment or differing levels of accuracy across groups.
LINK TO THIS THREATG AI.06Lack of Traceability of OutputsDecisions may lack a clear explanation or audit trail showing how an AI system reached them.
Limited explainability and inadequate documentation can prevent organisations and affected people from understanding the basis of a result. This makes errors, bias and manipulation harder to investigate.
LINK TO THIS THREATG AI.07Excessive AutonomyAn AI system may take actions beyond the authority or scope intended for it.
Broad permissions, uncontrolled tool calls or missing approval steps can let an agent act without an effective boundary. Overreliance on the system’s decisions can further reduce oversight.
LINK TO THIS THREATG AI.08Unbounded Resource ConsumptionExpensive inference requests or agent loops can exhaust quotas and drive unexpectedly high operating costs.
Consumption can vary with inputs and model behaviour, making per-request demand hard to anticipate. Agent loops can also consume the quotas, compute time and storage of connected services without an external attack.
LINK TO THIS THREATG AI.09Insecure Handling of AI OutputUnchecked AI output can become executable input in downstream applications.
Generated commands, queries or code can cause harm when validation and encoding are missing at the integration boundary. The issue is that the output takes effect unchecked, whether it was maliciously influenced or unintentionally wrong.
LINK TO THIS THREATG AI.10Model Extraction or TheftA model can be copied, reconstructed or stolen without authorisation.
Repeated queries can reveal enough behaviour to train a substitute, while stolen weights or artefacts allow direct reuse. The protected asset is the model itself, distinct from sensitive data inferred from it.
LINK TO THIS THREATG AI.11Deception by AI-generated ContentSynthetic or altered media can deceive people and obscure whether content is authentic or AI-generated.
Incoming audio, images, video or text can impersonate trusted people in communication and approval processes. An organisation’s own generated content can also lose traceable origin when labelling is absent or provenance information is removed or falsified.
LINK TO THIS THREATREFERENCES / 06
Sources and basis.
Selected references cited in my version 1.0 report. The threat grouping and working identifiers are my own proposal.
LINKS CHECKED /
- BSI — IT-Grundschutz: Elementary threats (opens in a new tab)
Structural reference · no edition specified in the report
Terminology, scope and level of abstraction for elementary threats. My report uses this structure to compare the proposed additions with existing scenarios.
- BSI — AI Security Concerns in a Nutshell (opens in a new tab)
Practical AI-Security Guide · v1.0 · 9 March 2023
Technical background on adversarial inputs, backdoors, information extraction and model stealing (§§3, 4.1, 4.2, 4.4 and 5.2).
- BSI — Generative KI-Modelle: Chancen und Risiken für Industrie und Behörden (opens in a new tab)
Version 2.0 · 17 January 2025
Risks in generated code, discriminatory outputs, deepfakes and unchecked execution of model output (R5, R6, R10, R11 and R16).
- OWASP — Top 10 for LLM Applications (opens in a new tab)
2025 edition
Application threats including prompt injection, excessive agency, improper output handling and unbounded consumption (LLM01, LLM05, LLM06 and LLM10).
- MITRE — ATLAS (opens in a new tab)
Data release v5.6.0
Adversarial techniques involving AI service exhaustion, cost harvesting and model extraction (AML.T0029, AML.T0034, AML.T0024.002 and AML.T0025). The link preserves the version used in the report.
- EDPS — Guidance for Risk Management of Artificial Intelligence Systems (opens in a new tab)
11 November 2025
Risk-management guidance on interpretability and explainability, data drift and bias. Chapter 4 informs the distinction around traceability of outputs.