MITRE ATLAS™ · AI/ML Threat Landscape
AI System Coverage Map
Where native Windows event logging can and can't evidence attacks against AI/ML systems.
Scope: ATLAS covers a fundamentally different attack surface than ATT&CK — training pipelines, model weights, inference APIs, prompt injection. Most of it happens inside the AI application or model layer, not the Windows host, so most of this page is an honest map of what this catalog can't see, not a coverage claim.
Version: ATLAS is evolving fast — 14 tactics as of mid-2026, up from 13 a year earlier (a Credential Access tactic, AML.TA0013, was added), with newer agentic-AI tactics like Lateral Movement proposed but not yet finalized. Also renamed "ML Model Access"/"ML Attack Staging" to AI Model Access/AI Attack Staging — this page uses current terminology.