# AI Threat Model Toolkit schema: `PAISEH-TK-1.0` Source artifact: Chapter 9 **AI Threat Model** Complete `../common-artifact-header.md` first. Record trust, privacy, access, misuse, dependency, affected-party, assurance, governance, and residual-risk decisions. ## 1. Objectives and Scope - Source AI Fit and Risk Assessment Worksheet identity, version, and accepted decision IDs: - Source Context Assembly Plan identity, version, and permission/source-trust boundary: - Source Harness Control-Loop Diagram identity, version, and control/approval boundary: - Source Tool Permission Matrix identity, version, and authority/effect boundary: - Supporting Evaluation Plan identity, version, and assurance-evidence IDs: - Protected outcomes and assets: - Exact system, population, environment, and consequence: - Data classes and prohibited disclosures/effects: - Security, privacy, product, engineering, and governance owners: - Explicit non-goals: ## 2. Flows and Trust Boundaries | Actor/component | Data or action | Identity/authentication | Authorization change | Trust boundary | Sensitive-data handling | Owner | | --- | --- | --- | --- | --- | --- | --- | | | | | | | | | Include users, model, context sources, tools, stores, control plane, and external dependencies. ## 3. Threat Scenarios | Scenario | Preconditions/path | Target | Consequence/affected party | Prevention | Detection | Containment/recovery | Residual uncertainty | | --- | --- | --- | --- | --- | --- | --- | --- | | | | | | | | | | Cover prompt injection, data leakage, unauthorized action, unsafe output, abuse, dependency or supply-chain change, and relevant domain-specific threats. ## 4. Access, Privacy, and Dependencies - Principal, purpose, least authority, and enforcement point: - Retention, deletion, derived data, residency, and disclosure: - User notice, correction, appeal, and consent where applicable: - Component/model/data/provider identity and provenance: - Integrity, change notice, fallback, concentration, and exit risk: ## 5. Control Assurance | Control | Requirement/owner | Implementation reference | Evidence | Limitation/failure signal | Last exercise | Change trigger | | --- | --- | --- | --- | --- | --- | --- | | | | | | | | | ## 6. Governance and Residual Risk - Security incident and notification handoff triggers: - Governance decision-record identity, disposition, constraints, and expiry: - AI Release Manifest handoff: governance decision ID, enforceable constraints, and material-change triggers: - AI Operations Runbook handoff: security event classes, containment constraints, evidence rules, and restoration authority: - Reviewers, rights, disposition, conditions, and dissent: - Residual risk exact scope and rationale: - Accepting authority and authority basis: - Compensating control and monitoring: - Effective date, expiry, and reopening event: