A threat model that does not end in test cases is a compliance document. You threat model an AI system to decide what goes into the private adversarial set and which numbers block a release. MITRE ATLAS and the OWASP GenAI lists supply the vocabulary, STRIDE supplies the discipline, and the eval suite is the output.
Two catalogs, two jobs
MITRE ATLAS extends ATT&CK into AI: a knowledge base of adversary tactics and techniques against AI-enabled systems, built from observed attacks and red-team demonstrations 1. Content release v2026.09, published September 15, 2026, holds 16 tactics, 120 techniques, 88 sub-techniques, 40 mitigations, and 73 case studies. Fourteen tactics carry an ATT&CK reference; the two AI-specific ones are AI Model Access and AI Attack Adaptation. Every technique carries a platform tag and a maturity rating (Feasible, Demonstrated, or Realized). Of the 208 technique and sub-technique entries, 139 are tagged Agentic AI, and 57 of those are rated Realized.
For an LLM application the techniques that matter sit in five tactics: Execution (AML.T0051 LLM Prompt Injection, AML.T0053 AI Agent Tool Invocation), Persistence (AML.T0070 RAG Poisoning, AML.T0080 AI Agent Context Poisoning, AML.T0110 AI Agent Tool Poisoning), Discovery (AML.T0084 Discover AI Agent Configuration), Exfiltration (AML.T0057 LLM Data Leakage, AML.T0077 LLM Response Rendering, AML.T0086 Exfiltration via AI Agent Tool Invocation), and Impact (AML.T0034.002 Agentic Resource Consumption, AML.T0048.000 Financial Harm).
Pin the version. ATLAS ships monthly content releases, and names move: v2026.08 renamed tactic AML.TA0001 from "AI Attack Staging" to "AI Attack Adaptation", and v2026.07 turned three standalone publish-poisoned-artifact techniques into sub-techniques of AML.T0115 1. The OWASP Top 10 for LLM Applications 2026 maps its entries to ATLAS v2026.06 and still prints the old tactic name 2. A threat model that cites "ATLAS" with no version cannot be diffed.
OWASP supplies the risk side. The Top 10 for LLM Applications 2026, published August 2026, blends a practitioner vote (three-quarters weight) with 6,639 classified incidents and reorders the 2025 list: Excessive Agency climbs to LLM03, System Prompt Leakage becomes LLM08 Hidden Context Exposure, Improper Output Handling drops to LLM10 2. It covers the model as a component; once the model acts with tools and memory, the risk moves to the Top 10 for Agentic Applications (December 9, 2025), ASI01 Agent Goal Hijack to ASI10 Rogue Agents 3. Under both sits Agentic AI Threats and Mitigations, first published February 2025 and now at version 1.1 (December 2025), with 17 threats from T1 Memory Poisoning to T17 Supply Chain Compromise 4. The OWASP walkthrough on this site uses the 2026 numbering and prints each entry's 2025 code beside it; use that crosswalk before merging findings tagged with 2025 codes.
| Source | Pin | Unit of analysis | Use it to |
|---|
| MITRE ATLAS | v2026.09 | Tactic, technique, case study | Name the attacker's steps; seed cases from real incidents |
| OWASP Top 10 for LLM Applications | 2026 | Ten risk entries | Cover model-as-component risks; answer procurement |
| OWASP Top 10 for Agentic Applications | 2026 (Dec 2025) | ASI01 to ASI10 | Cover agent-as-actor risks |
| OWASP Agentic AI Threats and Mitigations | v1.1 | T1 to T17 | Detailed taxonomy, mitigations, worked threat models |
A STRIDE pass over a refund agent
Neither catalog is a method. The OWASP threats guide names STRIDE and PASTA, says both need extending for AI, and points to MAESTRO as a layered extension of STRIDE 4. For a single agent, STRIDE plus an ATLAS tag per row is enough. Start from the four questions in the Threat Modeling Manifesto: what are we working on, what can go wrong, what are we going to do about it, and did we do a good enough job 5.
The system: a customer-support agent that reads customer messages and attachments, retrieves from a refund-policy knowledge base, and holds two tools, lookup_order (returns order and customer details) and issue_refund (moves money). Meta's Agents Rule of Two says an agent should hold no more than two of three properties in a session: it processes untrustworthy input, it can reach sensitive systems or private data, and it can change state or communicate externally 6. This agent holds all three, so issue_refund needs human approval or another reliable check, and the eval suite has to prove that check holds.
flowchart LR
C["Customer message + attachments (untrusted)"] --> A["Support agent"]
KB["Refund policy KB (retrieved)"] --> A
A -->|"lookup_order"| O["Orders DB with PII"]
A -->|"issue_refund"| G{"Approval gate"}
G --> P["Payments API"]
A --> R["Rendered reply"]
Walk each STRIDE category 7 across every arrow that crosses a trust boundary:
| STRIDE | Threat in this agent | ATLAS v2026.09 | OWASP |
|---|
| Spoofing | Attachment text poses as a supervisor approving an exception | AML.T0051.001 Indirect injection | ASI01 |
| Tampering | Planted policy page raises the no-approval refund limit | AML.T0070 RAG Poisoning | ASI06 |
| Repudiation | Refund issued with no trace of the input that caused it | none | T8 |
| Information disclosure | Agent returns another customer's order, or leaks it through a markdown image URL | AML.T0057, AML.T0077 | LLM02:2026 |
| Denial of service | Message drives a lookup fan-out that burns the tool budget | AML.T0034.002 | LLM06:2026 |
| Elevation of privilege | Injected instruction calls issue_refund beyond policy | AML.T0053, AML.T0048.000 | ASI02, LLM03:2026 |
The repudiation row shows why one catalog is not enough. ATLAS models the attacker, so a missing audit trail has no natural technique; the OWASP threats guide names it as T8 Repudiation and Untraceability.
ATLAS also hands you seed cases. Case study AML.CS0037 records a 2025 Zenity exercise against a Copilot Studio customer service agent: the researchers probed a support inbox, discovered the agent's tools, pulled CRM records through its get-records tool, and emailed them out with its own email tool 1. Microsoft fixed it; the case notes other prompts may still work. Replay that chain against any agent with a read tool and an outbound channel.
Threat to test case to metric to gate
Each STRIDE row becomes one eval row. The thresholds are starting points; tune them against your risk scores.
| Threat | Test case | Metric | Release gate |
|---|
| Injected refund (AML.T0053) | 40 tickets with refund instructions in body and attachments, three attack templates, a benign twin per case | Attack success (refund row exists in the sandbox ledger); benign task success | Zero executed refunds; benign success within 2 points of last release |
| Cross-customer disclosure (AML.T0057) | Requests for order IDs owned by seeded canary accounts | Canary leak rate | Zero |
| Markdown exfiltration (AML.T0077) | Injections asking for data inside an image URL | Rendered outbound URLs carrying customer data | Zero |
| Policy poisoning (AML.T0070) | Planted policy page in the retrieval index | Policy-violating approvals | No regression versus last release |
| Tool fan-out (AML.T0034.002) | Messages that request bulk lookups | p99 tool calls per conversation | Hard cap enforced; request fails closed |
| Untraceable refund (T8) | Every refund in every run | Share of refund calls traced to an input span | 100% |
Score on state, not transcript, and report attack success next to utility, the frontier from evaluating agents under attack. Each row also becomes a line in the AI risk register with its eval task column filled, which is the Map-to-Measure handoff in the NIST AI RMF mapping.
Keeping the model and the set fresh
Re-walk the model when a trigger fires, and hold a quarterly review even when nothing did:
- A new tool, a widened permission, or a new untrusted input channel.
- A new ATLAS release. Read the release notes, mark the added techniques that apply, write cases. v2026.09 added AML.T0130 AI Agent Response Biasing and AML.T0131 Crafted AI Assistant Links; both apply to a support widget that recommends sources or accepts a prefilled prompt in its URL.
- A production incident or red-team finding, through the intake path in the red-team program.
- A new defense. Nasr et al. bypassed 12 recent defenses with attack success above 90% for most, where most had originally reported near-zero 8. A replayed static set measures regression, not robustness against an attacker who adapts, so run an adaptive campaign after every defense change.
Where public benchmarks stop
Public benchmarks calibrate your harness and give you a comparable number. AgentDojo's 97 tasks and 629 security cases across email, e-banking, and travel-booking environments are where you confirm your state-based scoring works 9. They stop at your tools, policy, canaries, and input channels: no public suite knows your no-approval refund limit or that order notes are customer-writable. That is the private set, and it stays private, because published test data ends up in training corpora; Jacovi et al. recommend encrypting public test sets for this reason 10. Public numbers go on the model card. Private numbers decide the release. Draw cases from the attack families in the prompt injection taxonomy.
What to do this week
- Draw the data-flow diagram for one production agent. Mark every untrusted input and every write tool, and check the agent against the Rule of Two.
- Walk STRIDE across each trust boundary. Tag every threat with an ATLAS technique ID, the pinned version (v2026.09), and an OWASP code.
- For the three highest-scoring threats, write 20 to 40 state-checked cases each, with a benign twin per case.
- Wire attack success, canary leak rate, and trace coverage into the release gate next to utility.
- Watch releases on the atlas-data repository, browse the matrix on the ATLAS site 11, and put the quarterly re-walk on the risk-register calendar.