The AI Attack SurfaceStanding
170 AI attacks, four weaknesses
Updated 12 August 2026 · Timeframe: Current snapshot
MITRE ATLAS catalogs 170 techniques for attacking AI systems. We mapped every one to the CWE weakness catalog by hand. They reduce to five weaknesses, and only four of those are AI-specific. Out of more than nine hundred CWEs, four describe something particular to AI. And 61% of the attacks have no equivalent in enterprise ATT&CK at all.
Why it matters
You can name an AI attack precisely from ATLAS. You usually cannot name the weakness it exploits, because it has never been catalogued. Standard scans and control frameworks will not describe your real AI risk yet — the defensive vocabulary has not caught up to the attack vocabulary.
What to do
- Security leaders. If you run an AI system, enumerate exposure from ATLAS, not from a control framework or a weakness scan — they do not have the words yet.
- Lean IT orgs. Learn the four AI weaknesses by name; standard tooling will not flag them.
- MSPs. Add AI/ML components to client asset inventories now; the attack surface is real and mostly outside the frameworks you already report on.
Our take
Naming the AI defensive gap precisely, from our own direct mappings, is exactly the evidence-first AI framing the market's tsunami narrative skips.