NIST AI 100-2e2025, finalized on March 24, 2025, is NIST's taxonomy and terminology of adversarial machine learning attacks and mitigations, updating the January 2024 edition (AI 100-2e2023). It covers attacks on both predictive AI (evasion, poisoning, privacy attacks) and generative AI (supply-chain attacks, direct and indirect prompt injection, misuse), organized by attacker goals, capabilities and knowledge, and includes a glossary intended to inform future security standards and practice guides.
| Document | NIST AI 100-2e2025 (Adversarial ML) — Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations (NIST AI 100-2e2025) |
| Issued by | National Institute of Standards and Technology — AI Risk Management Framework |
| Type | Report |
| Status | Final |
| Published | Mar 24, 2025 |
| Applies to | Voluntary reference for security, model-risk and fraud teams responsible for predictive and generative AI systems. |
| Official source | csrc.nist.gov ↗ |
| Use cases | Cybersecurity · Fraud detection · Generative & agentic AI · Model risk management |
What are the key points of NIST AI 100-2e2025 (Adversarial ML)?
- Authored by NIST's Computer Security Division with Northeastern University, Cisco, the UK AI Security Institute and the US AI Safety Institute.
- Predictive AI taxonomy: evasion, poisoning (data and model) and privacy attacks (membership inference, data reconstruction, model extraction), with mitigations for each.
- Generative AI taxonomy: AI supply-chain attacks, direct prompting attacks including jailbreaks, indirect prompt injection via retrieved or tool content, and misuse enablement; the 2025 edition adds agent- and RAG-related attack vectors.
- Classifies attacks by learning stage (training vs. deployment), attacker knowledge (white-box, gray-box, black-box) and objective (availability, integrity, privacy, misuse).
- Is a reference document, not a control standard; NIST positions it to underpin later security guidance such as the COSAiS control overlays and the Cyber AI Profile.
What did NIST AI 100-2e2025 (Adversarial ML) change for banks?
The taxonomy gives bank security and model-validation teams a shared, citable vocabulary for threats to fraud models, credit models and LLM applications — prompt injection, data poisoning and model extraction — that existing model-risk guidance never named. It is the reference most bank threat models for AI now cite, and the basis for the AI-security work NIST is building on it.
What is NIST AI 100-2?
NIST's taxonomy of adversarial machine learning: a structured catalogue of attacks on predictive and generative AI systems (evasion, poisoning, privacy attacks, prompt injection, supply-chain attacks) and corresponding mitigations, latest edition March 2025.
Does NIST AI 100-2 cover prompt injection?
Yes. The generative-AI section covers direct prompting attacks such as jailbreaks and indirect prompt injection delivered through documents, web content or tool outputs, and discusses mitigations.
| Date | Document | Status |
|---|---|---|
| Apr 7, 2026 | AI RMF critical-infrastructure profile (concept note) — Concept Note: AI RMF Profile on Trustworthy AI in Critical Infrastructure | Proposed |
| Jan 12, 2026 | CAISI RFI on AI agent security (2026) — Request for Information: Security Considerations for Artificial Intelligence Agents | Proposed |
| Dec 16, 2025 | NIST IR 8596 (Cyber AI Profile) — Cybersecurity Framework Profile for Artificial Intelligence (Cyber AI Profile), NIST IR 8596 — preliminary draft | Proposed |
| Aug 14, 2025 | NIST COSAiS control overlays — Control Overlays for Securing AI Systems (COSAiS): SP 800-53 overlays for generative, predictive and agentic AI | Proposed |
| Jul 26, 2024 | NIST AI 600-1 (Generative AI Profile) — Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1) | In force |
| Jan 26, 2023 | NIST AI RMF 1.0 — Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 | In force |
Follow every document these regulators publish
6 curated AI stories for banking executives · Every morning · Free
Subscribe to BankingNewsAI →