§43 · Lane 8 — Agent Infrastructure Standards & Toolchain
MITRE ATLAS the adversary tradecraft beneath OWASP failure modes
The MITRE Corporation (2026) · MITRE ATLAS
Bibliographic data
- Title
- MITRE ATLAS — Adversarial Threat Landscape for Artificial-Intelligence Systems
- Authors / Issuing body
- The MITRE Corporation
- Venue / Publisher
- The MITRE Corporation
- Year
- 2026
- Designation
- Standards Framework
- Licence
- Apache-2.0 (atlas-data repository; Copyright 2021-2026 MITRE)
- Canonical link
- https://atlas.mitre.org/
How to cite
The MITRE Corporation (2026). MITRE ATLAS — Adversarial Threat Landscape for Artificial-Intelligence Systems. The MITRE Corporation. https://atlas.mitre.org/.
MITRE knowledge base of real-world adversary tactics and techniques against AI-enabled systems, modelled on the ATT&CK structure. Current data (content release v2026.07): 1 matrix, 16 tactics, 101 techniques, 77 sub-techniques, 37 mitigations, 68 case studies.
Why it matters for NETEVO
MITRE ATLAS is the adversary-tradecraft layer of AI threat modelling. Modelled on the MITRE ATT&CK structure, it is a knowledge base of real-world adversary tactics and techniques against AI-enabled systems. Where OWASP names failure modes, ATLAS names adversary tradecraft — what an attacker does to realise a failure mode against an AI-enabled system. Its vocabulary covers the adversarial side of a threat narrative and complements OWASP's defensive failure-mode vocabulary.
Individual ATLAS techniques carry their own identifiers — for example AML.T0018 Manipulate AI Model, and the agentic-AI techniques added to the matrix through 2026. The August 2026 content release added agentic tradecraft directly: AI Agent Tool Poisoning, now sub-techniqued across the tool definition, its implementation and its runtime response, alongside Publish Poisoned AI Artifacts and Modify Prompt Construction Logic.
At the framework layer, ATLAS pairs with the MEASURE function of the NIST AI RMF: the NIST AI RMF establishes what to measure and manage; ATLAS establishes what adversaries are likely to do. The matrix is in an active expansion phase.
Where NETEVO applies this
- Agent Infrastructure Whitepaper — load-bearing — adversarial-tradecraft layer paired with OWASP failure modes
Who acts on this
Reading this usually means something has forced the question — a listing, an audit finding, a procurement questionnaire, a regulator's letter. The role pages below set out what NETEVO does about it, including where we would tell you not to engage.