Skip to content

AI Security: Prompt Injection, Data Leakage and Red Teaming · Frameworks: OWASP, MITRE ATLAS and NIST · lesson 4 of 17 · 13 min

MITRE ATLAS and NIST AI guidance

Three complementary references

OWASP tells you what the main application risks are. Two other bodies of work help you describe how attacks happen and how to manage AI risk as an organization:

  • MITRE ATLAS (Adversarial Threat Landscape for Artificial-Intelligence Systems): a knowledge base of adversary tactics and techniques against AI systems, modeled on MITRE ATT&CK, with case studies.
  • NIST publications: the AI Risk Management Framework (AI RMF 1.0, 2023), its Generative AI Profile (NIST AI 600-1, July 2024), and NIST AI 100-2 E2025, Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations (March 2025).

MITRE ATLAS

ATLAS organizes adversary behavior into tactics (the adversary's goal at a stage, such as reconnaissance, initial access, execution, exfiltration, impact) and techniques (how they achieve it). Techniques relevant to LLM apps include:

| Technique | ID | |---|---| | LLM Prompt Injection (direct and indirect sub-techniques) | AML.T0051 (e.g. AML.T0051.000 direct, AML.T0051.001 indirect) | | LLM Jailbreak | AML.T0054 |

ATLAS also covers techniques such as poisoning training data, publishing poisoned models, and exfiltration via ML inference APIs, and includes real-world case studies. IDs and names evolve; always check the live ATLAS site.

Why use it: red-team reports and detection rules become comparable across teams and vendors when each finding is tagged with a tactic and technique. Security operations teams that already use ATT&CK find ATLAS familiar.

NIST AI RMF and the Generative AI Profile

The AI RMF is voluntary guidance organized into four functions:

  • Govern: policies, roles, accountability, culture.
  • Map: context, intended use, impacts, risks.
  • Measure: assess, analyze and track risks (evals and red teaming live here).
  • Manage: prioritize and act on risks; respond and recover.

NIST AI 600-1, the Generative AI Profile, maps these functions to risks that are unique to or amplified by generative AI, including confabulation, information security, data privacy, information integrity, harmful bias, intellectual property and value-chain and component integration, with suggested actions. It is voluntary, but increasingly referenced in procurement and by enterprise customers.

NIST AI 100-2 E2025: attack taxonomy

This report gives precise terminology for attacks on predictive and generative AI across the lifecycle: attacker goals (availability, integrity, privacy, and for GenAI, misuse), capabilities and knowledge. The 2025 edition expanded coverage of generative AI, including indirect prompt injection and misaligned outputs. Use it when you need rigorous definitions for policy or research, and to avoid inventing your own vocabulary.

How the pieces fit

| Need | Reference | |---|---| | Which application risks should we cover? | OWASP LLM Top 10 (+ Agentic Top 10) | | How do adversaries operate, step by step? | MITRE ATLAS tactics and techniques | | How do we govern and manage AI risk organizationally? | NIST AI RMF + AI 600-1 | | What exactly do we call this attack? | NIST AI 100-2 E2025 |

Other frameworks you may meet: ISO/IEC 42001 (AI management systems), the EU AI Act's obligations for certain systems (including accuracy, robustness and cybersecurity requirements for high-risk AI), and national guidance from cyber agencies such as the UK's NCSC. Regional regulators in the UAE, Saudi Arabia and Pakistan are also issuing AI and data guidance; track what applies to your sector.

Worked example: tagging a finding

A red team at a Riyadh e-commerce company found that product Q&A retrieved seller-written descriptions containing hidden instructions that made the assistant recommend a competitor's store.

finding: RT-2026-014
title: Indirect prompt injection via seller product descriptions
owasp: [LLM01:2026 Prompt Injection, LLM05:2026 Data and Model Poisoning]
atlas: [AML.T0051.001 LLM Prompt Injection: Indirect]
nist_rmf: {function: Measure, action: "adversarial testing of third-party content paths"}
severity: high
evidence: transcript T-88 (redacted), seller listing ID 5521
remediation: sanitize and delimit seller content; output link allowlist; seller content review workflow
retest: RT-2026-014-R1

This tagging lets the security team aggregate findings, compare with industry case studies and report progress to leadership in a framework they recognize.

Pitfalls

  • Framework tourism: collecting frameworks without mapping them to real controls and tests.
  • Stale IDs: ATLAS and OWASP evolve; link to the live source.
  • Treating voluntary frameworks as compliance proof; they are guidance, and legal obligations differ by jurisdiction.

How to measure success

Every red-team finding is tagged with OWASP (with edition), ATLAS technique and an RMF function, and your AI risk register references NIST AI 600-1 risk areas.

Video lecture: MITRE ATLAS and NIST AI guidance

Lecture coming soon · 14 chapters · about 8 minutes. Read the full transcript below.

  1. MITRE ATLAS and NIST guidance
  2. Analogy: running a hospital
  3. MITRE ATLAS
  4. Key techniques
  5. NIST AI RMF 1.0
  6. NIST AI 600-1 (GenAI Profile)
  7. NIST AI 100-2 E2025
  8. How they fit
  9. Case: tagging a finding
  10. Example: the PDF that emailed out
  11. Common mistakes
  12. Deeper: from profile to register
  13. Watch me do it: tagging a finding
  14. Recap

Lecture transcript

MITRE ATLAS and NIST guidance

OWASP tells you what the main application risks are. But when you write a red-team report, brief your security operations center, or answer a regulator, you need two more things: a precise description of how attacks unfold, and a framework for managing AI risk across the organization. In this lecture you will learn MITRE ATLAS and the key NIST publications, and how to use them together with OWASP.

Analogy: running a hospital

An analogy for how these frameworks relate. Think of a hospital. OWASP is like the list of the most common infections to screen for. MITRE ATLAS is like the detailed medical literature describing how each infection spreads, stage by stage, with case reports. The NIST AI Risk Management Framework is like the hospital's governance: who is accountable, how risks are assessed, how incidents are handled. And NIST one hundred dash two is the medical dictionary, so everyone uses the same precise terms. You need all four to run a safe hospital.

MITRE ATLAS

MITRE ATLAS stands for Adversarial Threat Landscape for Artificial-Intelligence Systems. It is a knowledge base of how adversaries attack AI, modeled on the famous ATT and CK framework. It organizes behavior into tactics, which are the attacker's goals at each stage, like reconnaissance, initial access, execution, exfiltration and impact, and techniques, which are how they achieve those goals. It also includes real-world case studies.

Key techniques

Two techniques you will tag constantly: LLM prompt injection, identified as A M L dot T zero zero five one, with sub-techniques for direct and indirect injection, and LLM jailbreak, A M L dot T zero zero five four. ATLAS also covers poisoning training data, publishing poisoned models and exfiltration through inference APIs. Identifiers and names evolve, so always check the live site. The value is comparability: tagged findings can be aggregated and compared across teams and vendors.

NIST AI RMF 1.0

Now NIST. The AI Risk Management Framework, version one point zero from twenty twenty-three, is voluntary guidance organized into four functions. Govern: policies, roles and accountability. Map: context, intended use and impacts. Measure: assessing and tracking risks, which is where evals and red teaming live. And Manage: prioritizing, acting, responding and recovering.

NIST AI 600-1 (GenAI Profile)

NIST AI six hundred dash one, the Generative AI Profile published in July twenty twenty-four, maps those functions to risks unique to or amplified by generative AI. They include confabulation, information security, data privacy, information integrity, harmful bias, intellectual property, and value chain and component integration, each with suggested actions. It is voluntary, but increasingly referenced by enterprise customers and in procurement.

NIST AI 100-2 E2025

For precise terminology, NIST AI one hundred dash two, the twenty twenty-five edition published in March, gives a taxonomy of adversarial machine learning attacks across the lifecycle, including attacker goals, capabilities and knowledge. The twenty twenty-five edition expanded generative AI coverage, including indirect prompt injection. Use it when you need rigorous definitions for policy, research or contracts, rather than inventing your own vocabulary.

How they fit

How do they fit together? OWASP answers which application risks to cover. ATLAS answers how adversaries operate step by step. The NIST AI RMF and its GenAI Profile answer how to govern and manage AI risk as an organization. And NIST one hundred dash two answers what exactly to call an attack. You will also meet ISO forty-two thousand and one for AI management systems, the EU AI Act's robustness and cybersecurity requirements for high-risk systems, national cyber agency guidance, and regional regulators in the Gulf and Pakistan.

Case: tagging a finding

Here is what tagging looks like in practice. A red team at an e-commerce company in Riyadh found that seller-written product descriptions contained hidden instructions that made the assistant recommend a competitor's store. The finding was tagged as OWASP prompt injection and data poisoning with the twenty twenty-six edition, ATLAS indirect prompt injection, and the NIST Measure function, with evidence, severity, remediation and a retest ID. That lets leadership see progress in frameworks they already recognize.

Example: the PDF that emailed out

A simple example of mapping one attack across frameworks. An attacker hides instructions in a PDF that your assistant summarizes, making it email the summary to an outside address. OWASP twenty twenty-six: LLM zero one prompt injection, plus LLM zero three excessive agency because the email tool allowed it. ATLAS: indirect prompt injection, A M L dot T zero zero five one dot zero zero one, followed by exfiltration. NIST RMF: a Measure activity should have tested document injection, and a Manage activity handles the response. One incident, four views, each useful to a different audience.

Common mistakes

Common mistakes with frameworks. Collecting them like trophies without mapping any to real controls. Citing outdated identifiers, because both OWASP and ATLAS evolve. Treating voluntary guidance as proof of legal compliance, when obligations under laws like the EU AI Act, UK data protection law or regional regulations are separate. And writing reports only in framework language, which leadership cannot act on. Always pair the tag with a plain-English sentence about business impact.

Deeper: from profile to register

One level deeper on the NIST Generative AI Profile. Take its information security risk area and ask what it means for your agent: supply-chain checks on models and packages, red teaming before release, and incident procedures. Write those three actions into your AI risk register with owners. That turns a long framework into three concrete lines of work.

Watch me do it: tagging a finding

Watch me do it: tagging the Riyadh finding from the lesson in the shared findings log. Finding ID: RT twenty twenty-six zero fourteen. Title: indirect prompt injection via seller product descriptions. First, OWASP. The primary item is LLM zero one, twenty twenty-six, prompt injection. Because seller content is part of the retrieval corpus and persisted there, I add LLM zero five, data and model poisoning, with the edition year on both. Second, ATLAS. The technique is LLM prompt injection, indirect, identified as AML dot T zero zero five one dot zero zero one. I check the live ATLAS site to confirm the ID has not changed. Third, NIST AI RMF. The gap was in Measure: nobody tested third-party content paths. The remediation plan lives in Manage. Fourth, severity: high, because the assistant pointed real shoppers to a competitor. Fifth, evidence: a redacted transcript ID and the seller listing ID, stored in the restricted evidence bucket. Sixth, remediation: sanitize and delimit seller content, restrict output links to our domain, and add a seller-content review workflow. Seventh, a retest ID. Then I add one plain-English sentence for leadership: a seller could make our assistant send customers to a rival store; fixed by filtering seller text and blocking outside links.

Recap

Recap. Use OWASP for coverage, ATLAS for adversary behavior, the NIST AI RMF and GenAI Profile for organizational risk management, and NIST one hundred dash two for precise terms. Avoid framework tourism, link to live sources, and remember voluntary frameworks are not proof of legal compliance. Your next step: tag your last three security findings, or three abuse cases, with OWASP edition, ATLAS technique and RMF function.

Key takeaways

  • MITRE ATLAS catalogs adversary tactics and techniques against AI (e.g. AML.T0051 prompt injection, AML.T0054 jailbreak).
  • NIST AI RMF organizes risk work into Govern, Map, Measure and Manage; NIST AI 600-1 profiles GenAI-specific risks.
  • NIST AI 100-2 E2025 provides precise adversarial ML terminology, including indirect prompt injection.
  • Tag findings with OWASP (with edition), ATLAS technique and RMF function; frameworks are guidance, not legal compliance proof.

Try it

Tag three recent findings or abuse cases with OWASP (with edition), ATLAS technique and NIST RMF function in a shared findings log.