AI SECURITY / ADVANCED

Mapping The AI Security Frameworks: NIST AI 100-2, MITRE ATLAS, OWASP And SAIF

Several frameworks describe AI attacks and defences, each for a different job. This article explains what NIST AI 100-2, MITRE ATLAS, OWASP, Google SAIF and the joint agency guidelines are for, and how they line up.

Checked against primary sources and independently reviewed on . Sources are listed at the end.

Security teams starting on AI soon meet a crowd of frameworks. NIST has a taxonomy, MITRE has a knowledge base, OWASP has its Top 10, Google has its own framework, and national cyber agencies have issued joint guidelines. They overlap, but they are not competitors. Each answers a different question, and a mature programme uses several of them together.

This article explains what each one is for, whether it carries any legal weight, and how their categories map onto each other. It covers security frameworks only. Governance frameworks such as the NIST AI Risk Management Framework, ISO/IEC 42001 and the EU AI Act are covered in AI Governance And Regulation.

The Vocabulary: NIST AI 100-2

NIST AI 100-2 E2025, “Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations”, was published in March 2025.1 It is a common language for attacks on machine learning. It separates predictive AI, such as classifiers, from generative AI, and sorts attacks by lifecycle stage, by the attacker’s goal (availability, integrity, privacy and, for generative AI, enabling misuse) and by the attacker’s capabilities and knowledge.

Its predictive AI chapter covers evasion, poisoning and privacy attacks. Its generative AI chapter adds supply chain attacks, direct prompting attacks and indirect prompt injection, and briefly discusses the security of agents. NIST states that the document is voluntary guidance and is not intended to serve as or replace regulation.1 Use it when you need precise, neutral terms, for example in policies or contracts.

The Adversary Playbook: MITRE ATLAS

MITRE ATLAS is a knowledge base of how adversaries attack AI systems. It is structured like MITRE ATT&CK, with tactics (the attacker’s goal at each stage), techniques (how they achieve it), mitigations and case studies, and its entries cross-reference ATT&CK where an AI attack uses conventional steps.2

ATLAS now publishes monthly content releases. Counting the official data file for release 2026.09, dated 15 September 2026, gives 16 tactics, 120 techniques, 88 sub-techniques, 40 mitigations and 73 case studies.2 Counts published elsewhere vary, often because they include or exclude sub-techniques or refer to an older release, so always quote the version. Use ATLAS for threat modelling, red team planning and mapping detections, in the same way security operations teams already use ATT&CK.

The Developer Checklist: OWASP Top 10 For LLM Applications

The OWASP Top 10 for LLM Applications, covered in the first article of this group, is the most practical starting point for teams building LLM features. Each entry includes examples, mitigations and attack scenarios. The 2026 edition adds a single appendix that maps every entry to other frameworks, including MITRE ATLAS (pinned to content release 2026.06), MITRE ATT&CK, CWE, NIST AI 600-1, the NIST AI RMF and the Cloud Security Alliance’s AI Controls Matrix. For ATLAS it maps each entry to adversary tactics, the stages of an attack, rather than to individual techniques.3 That appendix is a ready-made crosswalk for teams that report against more than one framework. OWASP is community guidance and does not by itself create legal obligations.

The Lifecycle Programmes: SAIF And The Joint Guidelines

Two further documents describe what an organisation should do across the AI lifecycle rather than cataloguing attacks.

Google introduced its Secure AI Framework (SAIF) in June 2023.4 It has six core elements: extend strong security foundations to AI, bring AI into detection and response, automate defences, harmonise platform-level controls, adapt controls with faster feedback loops, and place AI risks in the context of surrounding business processes.5 SAIF is a vendor framework, useful as a programme checklist.

In November 2023 the UK NCSC and the US CISA published “Guidelines for Secure AI System Development”, which CISA reports were co-sealed by 23 cybersecurity organisations at home and abroad.6 The guidelines are organised into four stages: secure design, secure development, secure deployment, and secure operation and maintenance.7 They apply to all AI systems, not only the most advanced models. In May 2025 CISA, the NSA and the FBI, with international partners, added joint guidance focused on securing the data used to train and operate AI.8 These documents are government guidance, not law.

How The Frameworks Line Up

The table below is our own editorial mapping of common attack classes across the three catalogues that name attacks directly. None of the three bodies publishes this exact table: OWASP’s appendix maps to ATLAS tactics rather than techniques, and it does not map to NIST AI 100-2. Each cell uses the framework’s own name for the entry, so you can check it at the source. SAIF and the joint guidelines work at the level of programmes and lifecycle stages, so they do not appear as columns.

Attack ClassOWASP LLM Top 10 (2026)NIST AI 100-2 E2025MITRE ATLAS Technique
Prompt injection, direct and indirectLLM01 Prompt InjectionDirect prompting attacks (3.3); indirect prompt injection (3.4)AML.T0051 LLM Prompt Injection, with Direct and Indirect sub-techniques
JailbreakPart of LLM01A kind of direct prompting attack aimed at misuse (3.3)AML.T0054 LLM Jailbreak
Hidden instruction or system prompt extractionLLM08 Hidden Context ExposureDirect prompting with a privacy goal (3.3)AML.T0056 Extract LLM System Prompt
Data and model poisoningLLM05 Data and Model PoisoningPoisoning attacks (2.3); data and model poisoning in the generative AI supply chain (3.2.1, 3.2.2)AML.T0020 Training Data Poisoning
Supply chain compromiseLLM04 Supply ChainSupply chain attacks (3.2)AML.T0010 AI Supply Chain Compromise
Leakage of training or context dataLLM02 Sensitive Information DisclosurePrivacy attacks (2.4); information extraction from generative models (3.3.2)AML.T0057 LLM Data Leakage
Model extractionCovered under LLM06 Unbounded ConsumptionModel extraction (2.4.4)AML.T0024.002 Extract AI Model
Denial of service and cost abuseLLM06 Unbounded ConsumptionAvailability poisoning (2.3.1); availability attacks through indirect prompt injection (3.4.1)AML.T0029 Denial of AI Service; AML.T0034 Cost Harvesting
Evasion of a classifier-Evasion attacks (2.2)AML.T0015 Evade AI Model
An editorial crosswalk of attack classes prepared for this article, not an official mapping by OWASP, NIST or MITRE. OWASP IDs from the 2026 edition; NIST sections from AI 100-2 E2025; ATLAS technique IDs and names from release 2026.09. A dash means the framework has no separate entry for it.

Choosing What To Use

A workable division of labour looks like this. Use NIST AI 100-2 for definitions, so that policies and contracts mean the same thing to everyone. Use the OWASP Top 10 as the developer’s checklist during design and code review. Use MITRE ATLAS for threat modelling, red team scenarios and detection coverage. Use SAIF or the joint guidelines to check that the overall programme covers design, build, deployment and operation.

Two cautions apply. First, all of these documents change over time. OWASP and ATLAS both changed in 2026, so any mapping should state the versions it relies on, as OWASP’s own appendix does. Second, frameworks that list attacks are not a measure of risk in your environment. They help you ask the right questions; your own threat model, informed by what your AI systems can reach and do, decides which answers matter. Risks that come from autonomous agents are mapped separately by OWASP’s Top 10 for Agentic Applications and are covered in Agentic AI Security.

Footnotes

  1. NIST, AI 100-2 E2025, “Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations”, A. Vassilev et al., March 2025. csrc.nist.gov ↩ ↩2

  2. MITRE, “ATLAS data”, release 2026.09 (data format 6.0.0), 15 September 2026; counts taken from the file dist/v6/ATLAS-2026.09.yaml. github.com ↩ ↩2

  3. OWASP GenAI Security Project, “Appendix A: Related Framework Mappings”, OWASP Top 10 for LLM Applications 2026, August 2026. github.com ↩

  4. Google, R. Hansen and P. Venables, “Introducing Google’s Secure AI Framework”, 8 June 2023. blog.google ↩

  5. Google, “Secure AI Framework (SAIF)”. safety.google ↩

  6. CISA, “CISA and UK NCSC Unveil Joint Guidelines for Secure AI System Development”, 26 November 2023. cisa.gov ↩

  7. UK National Cyber Security Centre, “Guidelines for secure AI system development”, 27 November 2023. ncsc.gov.uk ↩

  8. CISA, NSA, FBI and international partners, “AI Data Security: Best Practices for Securing Data Used to Train & Operate AI Systems”, 22 May 2025. cisa.gov ↩

Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.