AIPolicyTracker
Voluntary MITRE · living knowledge base

MITRE ATLAS

A knowledge base of adversary tactics, techniques and case studies against machine-learning systems, with mitigations, modelled on ATT&CK. Openly licensed; techniques and mitigations are cited by identifier.

Duties mapped
1
Mappings
1
Jurisdictions
1
Mitigations used
1
Evidence types
12
Risk areas
15
Recorded incidents
1,147

Duties are what the law asks; controls are what an organisation operates to meet them; evidence is how it shows it did. Incidents are the harms the AI Incident Database has recorded under the risk areas those controls address.

How it is structured

Tactics group techniques (AML.Txxxx) across the attack lifecycle; each mitigation (AML.Mxxxx) names the techniques it addresses.

It is the vocabulary a red team already uses, so a control expressed as an ATLAS mitigation can be tested by the people who attack it.

Legal duties by mitigation

A duty appears under every mitigation its mapping cites, so the totals below exceed the 1 distinct duties. References that name no single mitigation are grouped at the end rather than dropped.

Other references 1 duty

Controls that cite this threat model

Each control is an original description of what an organisation operates. The reference is the mitigation it corresponds to, by number only.

Controls referencing MITRE ATLAS
ControlMitigationDuties servedEvidence
AI literacy and role-based training programme
Training programme
AML.M0018 User Training4AI training completion records, Role-to-curriculum training matrix, AI training curriculum and materials
AI system inventory and classification
Process
AML.M0023 AI Bill of Materials11AI system register, Risk-tier classification sign-off, AI intake and classification procedure
Accuracy, robustness, fairness and security testing
Technical measure
AML.M0008 Validate ML Model, AML.M0003 Model Hardening, AML.M0015 Adversarial Input Detection15Pre-release test report, Test plan and acceptance criteria, Release test sign-off
Adversarial and red-team testing for generative AI
Technical measure
AML.M0020 Generative AI Guardrails, AML.M0022 Generative AI Model Alignment8Red-team exercise report, Red-team rules of engagement and scenario library, Adversarial findings tracker
Automatic event logging and record retention
Technical measure
AML.M0024 AI Telemetry Logging8AI system event logs, Log schema and retention standard, Log integrity and retention check
Data governance and dataset documentation
Process
AML.M0007 Sanitize Training Data8Dataset documentation sheet, Data quality and bias check report, Dataset approval for use
Frontier model safety and security framework
Policy
AML.M0001 Limit Model Artifact Release, AML.M0005 Control Access to ML Models and Data at Rest9Published frontier safety framework, Dangerous-capability evaluation report, Threshold notification to an authority
Training-data provenance and copyright register
Process
AML.M0025 Maintain AI Dataset Provenance4Training source register, Copyright and rights-reservation policy, Public summary of training content

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.

Frequently asked questions

What is MITRE ATLAS?
A knowledge base of adversary tactics, techniques and case studies against machine-learning systems, with mitigations, modelled on ATT&CK. Openly licensed; techniques and mitigations are cited by identifier.
Does MITRE ATLAS make an organisation legally compliant?
No. Adoption evidences a management practice, not compliance with any statute. A crosswalk shows where the two overlap so existing evidence can be reused; it does not transfer legal obligations.