Skip to content

Threat Modelling AI Applications

A structured way to identify how an AI system could be attacked or misused before building defences.

Editorial team 1 min read

Threat modelling asks: what are we building, what can go wrong, what will we do about it, and did we do a good job? It adapts well to AI systems.

Map the System

Draw the data flows: users, prompts, models, retrieval sources, tools, outputs, logs and third parties. Mark trust boundaries — where untrusted content enters.

Identify Threats

For each component and flow, consider:

  • Prompt injection, directly and via retrieved content.
  • Data leakage in outputs, logs or to providers.
  • Excessive permissions for tools and agents.
  • Poisoned data or models.
  • Unsafe output handling.
  • Abuse: spam, fraud, cost exhaustion.
  • Traditional threats: authentication, access control, dependencies.

Frameworks like STRIDE, the OWASP LLM Top 10 and MITRE ATLAS help prompt thinking.

Assess and Prioritise

Estimate likelihood and impact, focusing on realistic attackers and your most sensitive assets.

Define Controls

Choose mitigations for high-priority threats, and record accepted risks.

Revisit

Update the model when you add tools, data sources or capabilities — each addition changes the threat landscape.

More in AI security

All AI security guides →
AI security Guide · 1 min

Introduction to AI Security

What AI security covers — attacks on models, data and AI applications — and how it differs from traditional security.

AI security 1 min read 29 Jun 2025

AI security Guide · 1 min

The OWASP Top 10 for LLM Applications

An overview of the widely used list of the most critical security risks for applications built on language models.

AI security 1 min read 28 Jun 2025

AI security Guide · 1 min

Jailbreaks: How They Work and How to Defend

How people try to get models to bypass their safety training, common techniques, and layered defences.

AI security 1 min read 27 Jun 2025

AI security Guide · 1 min

Indirect Prompt Injection

How attackers hide instructions in web pages, emails and documents that AI systems read, and why it's so dangerous for agents.

AI security 1 min read 26 Jun 2025