AgentReadyHomeAgent Listing
Home · AI Security Answers · Agentic AI threats & frameworks

What is MITRE ATLAS and how do I use it for AI security?

Grounded & cited · AI agent security

What MITRE ATLAS is

MITRE ATLAS (Adversarial Threat Landscape for Artificial-Intelligence Systems) is a globally accessible, living knowledge base of real-world adversary tactics, techniques, and case studies targeting AI and machine-learning systems — including modern generative-AI and agentic systems. It is the AI-security counterpart to MITRE ATT&CK: where ATT&CK catalogs how adversaries compromise conventional IT and OT, ATLAS catalogs how they attack the model, the ML pipeline, and the AI application around it.

How ATLAS extends ATT&CK

ATLAS deliberately mirrors ATT&CK's structure so the two interoperate, then adds an AI-specific layer:

ATLAS has expanded steadily to cover generative and agentic AI. The Lateral Movement tactic was added in v5.1.0 (November 2025), taking the matrix from 15 to 16 tactics, alongside an expanded agentic case-study corpus.

The canonical tactics (matrix columns)

Below are the verified ATLAS tactics with their canonical IDs and the kinds of techniques each contains. AI-native tactics are called out.

GenAI and agentic techniques to know

ATLAS has grown a distinct generative-AI and agentic technique set. The headline ones:

Accuracy note on IDs: a handful of recent GenAI/agentic technique numbers that circulate in summaries — including AML.T0011.002 ("Publish Poisoned AI Agent Tool"), AML.T0092, AML.T0093, and AML.T0094 — could not be independently confirmed in this pass and may be mis-numbered. Treat the specific numbers as unverified and confirm against atlas.mitre.org/techniques before citing the exact ID. The tactic names and IDs above are verified.

Mitigations: name them correctly

ATLAS pairs techniques with AML.Mxxxx mitigations (e.g. Verify AI Artifacts, Sanitize Training Data, Adversarial Input Detection, Generative AI Guardrails, AI Telemetry Logging, Restrict Number of AI Model Queries, Control Access to AI Models and Data at Rest, Encrypt Sensitive Information). For the agent-permission and human-oversight controls, use the canonical names exactly — these are commonly mis-stated:

Do not assert the older "least privilege" / "human-in-the-loop safeguards" labels against M0026/M0027 — they are non-canonical pairings.

Using ATLAS for threat-informed defense

ATLAS is meant to drive a concrete defensive workflow, the same way teams use ATT&CK:

The case-study corpus

ATLAS's distinguishing asset is its corpus of documented, real-world case studies (each an AML.CSxxxx ID, ~42 as of v5.1.0). Each case study reconstructs an actual or realistically demonstrated attack on an AI system as a sequence of ATLAS tactics and techniques — including incidents where attackers abused a model-provider API as a covert C2 channel for an AI-agent backdoor. Teams use the corpus to:

Bottom line

ATLAS gives engineers and security/compliance leads an ATT&CK-compatible, AI-specific common language: 16 tactics (14 borrowed from ATT&CK plus the AI-native AI Model Access and AI Attack Staging), a technique catalog that now spans classic adversarial ML through GenAI prompt injection/jailbreak and agent-tool abuse, mitigations to match, and a case-study corpus to keep the model honest. Use the verified tactic IDs and the canonical mitigation names (especially AML.M0026/AML.M0027/AML.M0029), and verify any recent technique ID against atlas.mitre.org before citing it.

Grounded in

How does your AI agent score?

Get a free, instant AI agent security readiness snapshot — mapped to NIST, OWASP & ISO — then unlock the full report with a prioritized, cited fix-list.

Get the AI Security & Compliance Brief
Grounded, practical guidance for securing AI agents — mapped to NIST, OWASP & ISO. Occasional, and you can unsubscribe anytime.

This AI-generated answer is for guidance only — not a certification, audit, or penetration test. Grounded in the NIST AI RMF, OWASP LLM Top 10, and ISO/IEC 42001 control text; verify applicability to your environment.