Agent Risk Taxonomy
The first granular taxonomy that turns AI-risk standards into hands-on security controls.

Core Risk Domains
Risk Categories
Framework Mappings
Specific Risk Scenarios
Built on Industry Standards
.avif)
OWASP Top 10 for Agentic Applications (2026)
10/10 covered (ASI01βASI10)
β

MITRE ATLAS
Live tactics & techniques like AML.T0053 (Plugin Compromise)

EU AI Act
Direct references to Articles 9, 10, 14 + Annex III.

NIST AI RMF
Each risk slotted into Govern β Map β Measure β Manage
ISO 42001 / 24028
Governance & trustworthiness clauses cross-linked.
AIUC-1
All six pillars mapped, A. Data & Privacy through F. Society.
Agent Risk Taxonomy
Theft
& Permission
ASI01 - ASI10

Frequently Asked Questions
We focus specifically on autonomous agents that use toolsβnot traditional ML models. The risks are fundamentally different.
Any AI system that can invoke external APIs, make decisions autonomously, or interact with tools. Technology-agnostic.
Unlike traditional frameworks that focus on ML model security, our taxonomy specifically addresses the unique risks of agentic AI systems that can take autonomous actions and interact with external tools.
Yes, the taxonomy covers single-model agents, multi-agent systems, and any AI system that can invoke external tools or APIs autonomously. It's designed to be technology-agnostic.
Yes! We welcome input from security practitioners. Contact us about our contributor program.

