Analysis

AI Agent Threat Models: 60+ in 14 Categories

Page published

Publication date unknown · First observed: 10 Oct 2026

Coverage timeline

10 Oct 2026ackuity.aiobserved

Single-source analysis — one report is available.

Why it matters

Ackuity's taxonomy gives defenders a structured vocabulary for enumerating and reasoning about the attack surface of autonomous AI agents across memory, tools, identity, and MCP integrations.

Ackuity publishes a reference taxonomy organizing 60+ AI agent threat models into 14 categories, including A2A threats, memory poisoning, privilege compromise, tool misuse, prompt injection (direct, indirect, XPIA), MCP threats, and sensitive data exposure. Each category lists example threat models described in plain-English reference form rather than any specific current event or new finding.