Evidence library · Communities and Working groups

MITRE ATLAS

The adversarial threat landscape for AI systems: tactics, techniques, and case studies, including agentic-system techniques.ATLAS is a threat catalog. It supplies the why for controls, not the what. It is not a control framework.

Last reviewed:

A note on MITRE ATLAS and how AAES control rows relate to its technique families. Because ATLAS catalogs threats rather than controls, this page maps threat families to the controls designed against them — it is not a coverage scorecard.

These pages describe the product. They are not a certification or a legal opinion.

Reading this note

ATLAS is authoritative for its own tactics, techniques, and case studies. Technique identifiers drift as ATLAS renumbers, so this note cites technique families by name and dates its review rather than pinning identifiers. AAES claims no coverage percentages it has not measured.

Instrument identity

Title
MITRE ATLAS (Adversarial Threat Landscape for Artificial-Intelligence Systems)
Issuing body
MITRE
Instrument type
Adversarial threat knowledge base: tactics, techniques, and case studies, including agentic-system techniques such as prompt injection, tool misuse, and agent orchestration abuse. A threat catalog, not a control framework.
Official source
atlas.mitre.org

Question

For the agentic technique families ATLAS names, which AAES controls are designed against them?

For a reviewer with an ATLAS mental model: pre-execution interception, intent-aligned policy, and authorization decisions (AARM rows R1, R3, R4) are the controls designed against the tool-misuse and action-execution techniques; the provenance trichotomy (R11) addresses untrusted-content techniques; behavioral analytics (R9) supports detection coverage. For procurement teams, this is the answer to "which threats do your controls address" — with the boundary that AAES constrains actions, it does not detect attacks in model input.

Selected contribution

Selected ATLAS technique families and AAES control boundaries
Technique familyWhat a reviewer can examine in AAESBoundary
Tool misuse and action executionAgents only see permitted capabilities; actions classified as irreversible require approval by an authorized person; an agent cannot approve itself; recorded decisions are sealed in a hash-chained record.Enforcement depends on control of the agent's credential path. An action that satisfies the configured policy may still be authorized.
Untrusted content and prompt injectionContent provenance is classified at decision time, and an injected instruction that tries to become an action still has to pass the same decision as a legitimate one.AAES does not detect or prevent prompt injection in model input. It constrains what a routed action can do, whether the instruction was legitimate or injected.
Agent orchestration abuseDelegation chains with verified per-hop narrowing and behavioral analytics over recorded decisions support detection of anomalous sequences.Analytics describe recorded activity on the governed path; activity outside AAES is visible only where telemetry is supplied.

Preconditions and gaps

  • A catalog, not a checklist. ATLAS supplies the why for control rows; mapping to it does not establish coverage, and AAES publishes no coverage percentages it has not measured.
  • Techniques drift. This mapping is dated 27 September 2026 and will be refreshed when ATLAS ships an update.
  • Credential-path control is required. Activity outside AAES is visible only where telemetry is supplied. Observation is not enforcement.
  • AAES is not a detection product. No AAES penetration test or SOC 2 report exists today; see security disclosures.

For implementation and testing details beyond this note, use Security and implementation posture and the evaluation page. Results from a client's test tenant are produced during a scoped evaluation.

Client responsibility

The organization runs its own threat modeling against ATLAS. The client remains the regulated entity.

Identify the credential path, actions, and evidence questions to examine in a client test tenant.

Scope an evaluation