Threat Taxonomy
TopAIThreats classifies AI-enabled threats using a multi-dimensional taxonomy. The core hierarchy — domains, patterns, and incidents — is complemented by four stakeholder dimensions (affected groups, exposure pathways, ecosystem positions, and impact level) and six analytical dimensions (causal factors, harm types, assets, attack lifecycle, governance frameworks, and risk levels).
Core hierarchy: Domain → Pattern → Incident
Domains: 8 | Patterns: 48 | Exposure Pathways: 5 | Causal Factors: 15 | Assets: 12 | Harm Types: 7 | Frameworks: 3
Machine-readable: /api/threats.json
Agentic & Autonomous Threats
Threats caused by AI systems that act independently, persist over time, or coordinate with other systems.
Human–AI Control Threats
Threats arising from how humans rely on, defer to, or lose control over AI systems.
Economic & Labor Threats
Threats that distort markets, labor conditions, or the distribution of economic power.
Information Integrity Threats
Threats that undermine the reliability, authenticity, or shared understanding of information.
Privacy & Surveillance Threats
Threats involving unauthorized inference, tracking, or monitoring of individuals or groups.
Security & Cyber Threats
AI-enabled attacks that compromise the integrity, confidentiality, or availability of digital systems — through input manipulation, model exploitation, or automated offense.
PAT-SEC-001 Adversarial Evasion PAT-SEC-008 AI Supply Chain Attack PAT-SEC-002 AI-Morphed Malware PAT-SEC-009 AI-Powered Social Engineering PAT-SEC-003 Automated Vulnerability Discovery PAT-SEC-004 Data Poisoning PAT-SEC-007 Jailbreak & Guardrail Bypass PAT-SEC-005 Model Inversion & Data Extraction PAT-SEC-006 Prompt Injection Attack Discrimination & Social Harm
Threats that result in unfair treatment, exclusion, or social harm to individuals or groups.
Systemic & Catastrophic Risks
Threats that emerge from scale, coupling, and accumulation rather than single failures.
PAT-SYS-001 Accumulative Risk & Trust Erosion PAT-SYS-002 AI-Assisted Biological Threat Design PAT-SYS-003 Infrastructure Dependency Collapse PAT-SYS-004 Lethal Autonomous Weapon Systems (LAWS) PAT-SYS-005 Strategic Misalignment PAT-SYS-006 Uncontrolled Recursive Self-Improvement (Hypothetical) Stakeholder Dimensions
Four dimensions capture who is affected, how they are exposed, who is responsible, and the scale of impact.
Affected Groups
Who is directly harmed by AI-enabled threats, organized into three categories.
Individuals
Organizations
Systems
Individuals
Organizations
Systems
Exposure Pathways
How individuals and organizations encounter AI-enabled threats.
Ecosystem Positions
Who caused, enabled, or failed to prevent an AI-enabled threat.
Impact Level
Scale of harm from an individual incident.
Analytical Taxonomy Dimensions
Additional dimensions classify contributing factors, technologies involved, harm categories, governance frameworks, and risk levels.
Harm Types
Categories of harm that AI-enabled threats can inflict on individuals, organizations, and society.
Governance Frameworks
Regulatory and governance frameworks relevant to AI threat mitigation and compliance.
Causal Factors
Contributing factors that enabled or amplified AI-enabled threats, across four categories.
Malicious Misuse
CAUSE-001 Intentional Fraud CAUSE-002 Adversarial Attack CAUSE-003 Weaponization CAUSE-004 Social Engineering Design & Development
CAUSE-005 Training Data Bias CAUSE-006 Insufficient Safety Testing CAUSE-007 Hallucination Tendency CAUSE-008 Model Opacity Deployment & Integration
CAUSE-009 Inadequate Access Controls CAUSE-010 Over-Automation CAUSE-011 Prompt Injection Vulnerability CAUSE-012 Misconfigured Deployment Systemic & Organizational
CAUSE-013 Regulatory Gap CAUSE-014 Accountability Vacuum CAUSE-015 Competitive Pressure Assets & Technologies
AI technologies and data types involved in documented threat incidents.
Data
ASST-002 Biometric Data ASST-007 Identity Credentials ASST-011 Training Datasets Model
ASST-006 Foundation Models ASST-009 Large Language Models ASST-010 Recommender Systems ASST-012 Voice Synthesis System
ASST-001 Autonomous Agents ASST-003 Content Platforms ASST-004 Decision Automation Infrastructure
ASST-005 Financial Systems ASST-008 Industrial Control Systems Risk Levels
Severity, likelihood, and reversibility assessments applied to incidents and patterns.
Critical, High, Medium, Low — applied to patterns and incidents
Reversible, Partially Reversible, Irreversible — recoverability of harm