MITRE ATLAS

ATLAS is modeled after and complementary to ATT&CK — a standalone knowledge base, not a matrix inside it. Its 2026 releases are dominated by agentic techniques.

MITRE ATLAS — Adversarial Threat Landscape for AI Systems — is a public knowledge base of adversary tactics, techniques and mitigations aimed at AI systems, together with case studies of real incidents. It is a reference for what attackers actually do, not a control framework you comply with.

How it relates to ATT&CK

MITRE describes ATLAS as modeled after and complementary to ATT&CK. It reuses the structural conventions — tactics, techniques, sub-techniques, mitigations — and it is a standalone knowledge base with its own identifier namespace, not a matrix inside ATT&CK. Saying ATLAS is part of ATT&CK is a common and checkable error.

One structural feature ATT&CK does not have in the same form: case studies, identified as AML.CS####, documenting real incidents against real systems. For a security team building a threat model, those are often more useful than the technique list, because they show which techniques have actually been chained together.

What is in it, and how fast it moves

As of release v2026.08, dated 1 September 2026, ATLAS contained 16 tactics, 114 techniques, 83 sub-techniques, 39 mitigations and 72 case studies. Pin any figure to a version, because it is updated roughly monthly and the technique count grew by more than a tenth across the two preceding releases alone.

The direction of travel is the part worth noting. The 2026 releases are dominated by autonomous and agentic content — techniques covering autonomous reconnaissance, attack-path adaptation, inter-agent communication and attack orchestration, plus mitigations named AI Agent Authority Expansion Controls and AI Agent Scope Drift Detection. Earlier 2026 releases added agent tool poisoning and guardrail bypass.

Since the May 2026 release every technique also carries a platform designation — Predictive AI, Generative AI, Agentic AI or Enterprise — which makes it possible to filter the knowledge base down to the systems an organization actually runs.

Using it without misusing it

ATLAS is a threat reference, so it fits three jobs and not others.

Threat modeling. Which techniques apply to this deployment, and which mitigations are in place for each.

Red team scoping. A source of techniques to attempt, so testing is measured against a shared catalogue rather than an individual's imagination — see AI red teaming.

Control mapping. Showing which enforced controls address which techniques, which is the form a security committee can review.

What it is not is a compliance framework. There is no certification, no audit scheme and no authority behind it — that role belongs to ISO/IEC 42001 and NIST AI RMF. Mapping controls to ATLAS is useful evidence; claiming compliance with ATLAS is a category error.

Two mitigation names in the 2026 releases describe precisely the control this site argues for — bounding what authority an agent can accumulate, and detecting when its scope drifts. See agent authority scope, runtime governance and agentic governance.

AI red teaming · Prompt injection · Tool poisoning · ISO/IEC 42001 · Full glossary

Counts verified against the MITRE ATLAS v2026.08 release notes, 1 September 2026.

Put this in the path of your own agents.

Policy enforced inline between your agents and every model and tool they reach, with a record bound to the human who owns it.

Request a Demo Read the docs