Framework / MITRE / Release 2026.09
MITRE ATLAS explained: tactics, techniques and tests.
MITRE ATLAS is a public knowledge base of the tactics and techniques adversaries use against AI systems, maintained by MITRE and structured like ATT&CK. Its September 2026 release lists 16 tactics and 120 techniques, from reconnaissance to impact, each with an id such as AML.T0051 that a test plan and a report can share.
Retrieved / KB/0212 / Slenkwater Verzekeringen / fiction
Water damage from a burst pipe is covered up to the policy limit.
A claim is assessed within ten working days of the report.
A line a reviewer does not see and the model reads as an order. Its text is not shown on this site.
Questions this page does not answer go to the claims desk.
What is MITRE ATLAS?
MITRE ATLAS, the Adversarial Threat Landscape for AI Systems, is a public knowledge base of how adversaries attack systems that include machine learning or generative AI. It records what attackers try to achieve, the techniques they use to get there, and the documented cases where those techniques were shown to work.
MITRE publishes it twice over: as a browsable matrix on atlas.mitre.org,1 and as versioned data in a public repository, where it describes ATLAS as a knowledge base of adversary tactics, techniques and procedures targeting AI systems.2 This piece uses release 2026.09, dated 15 September 2026.3
If you know MITRE ATT&CK, the shape is familiar on purpose. Fourteen of the sixteen ATLAS tactics point to an ATT&CK tactic, from Reconnaissance to Impact. Two exist only in ATLAS, because they only make sense against AI: AI Model Access and AI Attack Adaptation.4
How is ATLAS organised?
Three layers do the work. A tactic is the adversary’s goal at a step, such as Initial Access or Exfiltration. A technique is how they reach it, such as LLM Prompt Injection, AML.T0051. A sub-technique is a variant, such as AML.T0051.001, the indirect form. Release 2026.09 holds 16 tactics, 120 techniques and 88 sub-techniques, with 40 mitigations and 73 case studies alongside (Fig. 1).5
Reconnaissance
0 of 9 in our plan
Resource Development
0 of 9 in our plan
Initial Access
3 of 10 in our plan
AI Model AccessAI only
0 of 4 in our plan
Execution
4 of 6 in our plan
Persistence
7 of 11 in our plan
Privilege Escalation
2 of 4 in our plan
Defense Evasion
7 of 18 in our plan
Credential Access
2 of 7 in our plan
Discovery
2 of 10 in our plan
Lateral Movement
1 of 5 in our plan
Collection
1 of 6 in our plan
AI Attack AdaptationAI only
0 of 11 in our plan
Command and Control
0 of 5 in our plan
Exfiltration
4 of 6 in our plan
Impact
4 of 10 in our plan
Every technique carries two tags that make the knowledge base practical. Platforms say which kind of system it applies to: predictive AI, generative AI, agentic AI or the enterprise around them. In this release Agentic AI is the most common tag, on 139 of 208 technique and sub-technique entries. A maturity level, from feasible to realized, says how far the technique has been taken.6
The mitigations sit on the other side of the same links. Each one is tagged as a policy measure, an AI-specific technical control or a conventional cyber control, and each points at the techniques it addresses. That makes the matrix usable in both directions: from a technique to the controls that blunt it, and from a control you already have to the techniques it leaves uncovered.
The case studies are what keep it honest. Of the 73, 50 are exercises, red team and research demonstrations, and 23 are incidents. Each one is written as a sequence of techniques, which is exactly the form a test plan needs.5
How does ATLAS compare with the OWASP Top 10?
They look at the same systems from opposite ends. The OWASP Top 10 for LLM Applications ranks what can go wrong in an application; ATLAS describes what an attacker does to make it go wrong. The 2026 OWASP edition maps its risks to ATLAS, so the two meet in the ids.7
| OWASP LLM Top 10 | MITRE ATLAS | |
|---|---|---|
| Point of view | The defender’s: what can go wrong | The attacker’s: what they do, step by step |
| Unit | A risk category | A technique toward a tactic |
| Size | 10 categories | 16 tactics, 120 techniques |
| Order | Ranked by risk | Grouped by the adversary’s goal |
| Evidence | Community ranking weighed against incident data | Case studies and a maturity level per technique |
| Best for | Prioritising and reporting | Test plans, threat models and detection |
In a report we use both. Each finding gets its OWASP id, so a reader knows which risk it is, and its ATLAS technique, so a defender knows what the attacker did and what to watch for. Our guide to the OWASP Top 10 for LLM Applications 2026 covers the other side.
How do ATLAS ids become a test plan?
We start from our own catalogue of 54 test categories, the things we check in an AI or stack engagement. Every AI category lists the ATLAS techniques it exercises. Rolled up to parent techniques, that is 32 of the 120 in this release, and the count is recomputed whenever the catalogue or the release changes.
We track sub-techniques where the difference changes the test, such as direct and indirect prompt injection, and count parents where it does not. Releases add and retire ids, so the site’s own build checks every ATLAS id in the plan against the pinned release and refuses to publish a plan that cites an id the release no longer has. The same rule applies to a report: it names the release it was mapped to.
| Test category | Primary id | ATLAS |
|---|---|---|
| Prompt injection resistance, direct and indirect | LLM01:2026 | AML.T0051, AML.T0051.000, AML.T0051.001, AML.T0054, AML.T0068, AML.T0093, AML.T0129 |
| Consumption limits and denial of wallet controls | LLM06:2026 | AML.T0034, AML.T0034.002, AML.T0029 |
| Tool and function calls kept within the task's intended scope | ASI02 | AML.T0053, AML.T0086, AML.T0101 |
| Agentic supply chain: MCP servers, plugins and tool definitions | ASI04 | AML.T0010.005, AML.T0011.002, AML.T0110, AML.T0109 |
Fig. 1 shows where the plan sits. It is dense in Execution, Persistence, Defense Evasion, Exfiltration and Impact, the steps that happen inside your system. It is empty in Reconnaissance, Resource Development, AI Model Access, AI Attack Adaptation and Command and Control. Those describe what an attacker does on their own side, before and around the attack, and an authorized test of your application has no reason to reproduce them.
The 32 techniques in our test plan
- AML.T0010 AI Supply Chain Compromise
- AML.T0011 User Execution
- AML.T0020 Training Data Poisoning
- AML.T0029 Denial of AI Service
- AML.T0034 Cost Harvesting
- AML.T0050 Command and Scripting Interpreter
- AML.T0051 LLM Prompt Injection
- AML.T0053 AI Agent Tool Invocation
- AML.T0054 LLM Jailbreak
- AML.T0056 Extract LLM System Prompt
- AML.T0057 LLM Data Leakage
- AML.T0061 LLM Prompt Self-Replication
- AML.T0062 Discover LLM Hallucinations
- AML.T0067 LLM Trusted Output Components Manipulation
- AML.T0068 LLM Prompt Obfuscation
- AML.T0069 Discover LLM System Information
- AML.T0070 RAG Poisoning
- AML.T0071 False RAG Entry Injection
- AML.T0077 LLM Response Rendering
- AML.T0080 AI Agent Context Poisoning
- AML.T0081 Modify AI Agent Configuration
- AML.T0083 Credentials from AI Agent Configuration
- AML.T0085 Data from AI Services
- AML.T0086 Exfiltration via AI Agent Tool Invocation
- AML.T0093 Prompt Infiltration via Public-Facing Application
- AML.T0098 AI Agent Tool Credential Harvesting
- AML.T0101 Data Destruction via AI Agent Tool Invocation
- AML.T0109 AI Supply Chain Rug Pull
- AML.T0110 AI Agent Tool Poisoning
- AML.T0129 Triggers in Multimodal Inputs
- AML.T0130 AI Agent Response Biasing
- AML.T0132 Misconfigured or Publicly Exposed AI Services
How should defenders use ATLAS?
Use it to ask better questions of your own system. Walk the rows of Fig. 1 that apply to you and, for each technique, ask three things: could an attacker do this here, would we notice, and what would stop it? The second question is the easiest to skip. A feature that logs only the user’s message and the final answer misses the retrieved passages, the tool calls and the arguments the model chose, which is where most of these techniques leave their traces.
For the third question, ATLAS links each technique to mitigations. LLM Prompt Injection alone has seven, among them AI Red Team, AI Telemetry Logging and input and output validation for agent components.8
For agents, start where the agent acts. Prompt injection steers it; AI Agent Tool Invocation turns that into actions; AI Agent Context Poisoning keeps it steered; Exfiltration via AI Agent Tool Invocation carries data out in an action that looks legitimate.9 Our prompt injection explainer follows that chain end to end.
The defensive takeaway: a technique id in a report should point to a test that actually ran, and to a control that would have stopped it. An id on its own is a label, not a finding.
Questions people ask
What does MITRE ATLAS stand for?
Adversarial Threat Landscape for AI Systems. It is MITRE’s public knowledge base of the tactics and techniques adversaries use against systems that include machine learning or generative AI, published as a matrix on atlas.mitre.org and as versioned data releases that tools and test plans can read.
Is MITRE ATLAS the same as MITRE ATT&CK?
No, but they share a shape. ATT&CK describes adversary behaviour against enterprise IT; ATLAS describes attacks on AI systems. Fourteen of the sixteen ATLAS tactics point to an ATT&CK tactic, while AI Model Access and AI Attack Adaptation exist only in ATLAS.
Do we need ATLAS if we already use the OWASP Top 10 for LLM Applications?
They answer different questions. The OWASP lists rank what can go wrong in your application; ATLAS describes what an attacker does, technique by technique, to make it go wrong. Use OWASP to prioritise and to report, and ATLAS to build the test plan and the threat model, and to name what you detect.
Which ATLAS techniques matter most for an AI agent?
Start where the agent acts: LLM Prompt Injection (AML.T0051), AI Agent Tool Invocation (AML.T0053), AI Agent Context Poisoning (AML.T0080) and Exfiltration via AI Agent Tool Invocation (AML.T0086). Together they describe how an agent is steered, made to use its tools, kept steered, and used to move data out.
Where we test this
AI Pentest / Agent and MCP
What an agent can reach: its tools, its memory, its tokens and the systems behind them.
AI Pentest / Chatbot and RAG
LLM and chatbot penetration testing
Prompt injection, data leakage and cross-tenant retrieval in chatbots and RAG applications.
AI Pentest / Model layer
Adversarial testing of chatbots, RAG applications and agents, mapped to OWASP and MITRE ATLAS.
Method
Scoping, threat model, testing, verification, severity, reporting and retest.
Sources
Every factual sentence above carries a numbered note; these are the documents behind them.