# NIST AI 100-2e2025 (Adversarial ML): Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations (NIST AI 100-2e2025)

Source: https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-100-2e2025
Last updated: Aug 26, 2026

NIST AI 100-2e2025, finalized on March 24, 2025, is NIST's taxonomy and terminology of adversarial machine learning attacks and mitigations, updating the January 2024 edition (AI 100-2e2023). It covers attacks on both predictive AI (evasion, poisoning, privacy attacks) and generative AI (supply-chain attacks, direct and indirect prompt injection, misuse), organized by attacker goals, capabilities and knowledge, and includes a glossary intended to inform future security standards and practice guides.

## At a glance

| Field | Value |
| --- | --- |
| Authority | [NIST](https://www.bankingnewsai.com/ai-regulation/nist) |
| Type | Report |
| Status | Final |
| Published | Mar 24, 2025 |
| Applies to | Voluntary reference for security, model-risk and fraud teams responsible for predictive and generative AI systems. |
| Official text | https://csrc.nist.gov/pubs/ai/100/2/e2025/final |

## Key points

- Authored by NIST's Computer Security Division with Northeastern University, Cisco, the UK AI Security Institute and the US AI Safety Institute.
- Predictive AI taxonomy: evasion, poisoning (data and model) and privacy attacks (membership inference, data reconstruction, model extraction), with mitigations for each.
- Generative AI taxonomy: AI supply-chain attacks, direct prompting attacks including jailbreaks, indirect prompt injection via retrieved or tool content, and misuse enablement; the 2025 edition adds agent- and RAG-related attack vectors.
- Classifies attacks by learning stage (training vs. deployment), attacker knowledge (white-box, gray-box, black-box) and objective (availability, integrity, privacy, misuse).
- Is a reference document, not a control standard; NIST positions it to underpin later security guidance such as the COSAiS control overlays and the Cyber AI Profile.

## What changed for banks

The taxonomy gives bank security and model-validation teams a shared, citable vocabulary for threats to fraud models, credit models and LLM applications — prompt injection, data poisoning and model extraction — that existing model-risk guidance never named. It is the reference most bank threat models for AI now cite, and the basis for the AI-security work NIST is building on it.

## Use cases it governs

- [Cybersecurity](https://www.bankingnewsai.com/ai-regulation/by-use-case#cybersecurity)
- [Fraud detection](https://www.bankingnewsai.com/ai-regulation/by-use-case#fraud)
- [Generative & agentic AI](https://www.bankingnewsai.com/ai-regulation/by-use-case#generative-agentic-ai)
- [Model risk management](https://www.bankingnewsai.com/ai-regulation/by-use-case#model-risk)

## FAQ

### What is NIST AI 100-2?

NIST's taxonomy of adversarial machine learning: a structured catalogue of attacks on predictive and generative AI systems (evasion, poisoning, privacy attacks, prompt injection, supply-chain attacks) and corresponding mitigations, latest edition March 2025.

### Does NIST AI 100-2 cover prompt injection?

Yes. The generative-AI section covers direct prompting attacks such as jailbreaks and indirect prompt injection delivered through documents, web content or tool outputs, and discusses mitigations.

## Related documents

- [AI RMF critical-infrastructure profile (concept note)](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-rmf-critical-infrastructure-profile-concept-note) — Concept Note: AI RMF Profile on Trustworthy AI in Critical Infrastructure (Apr 7, 2026)
- [CAISI RFI on AI agent security (2026)](https://www.bankingnewsai.com/ai-regulation/documents/nist-caisi-rfi-ai-agent-security-2026) — Request for Information: Security Considerations for Artificial Intelligence Agents (Jan 12, 2026)
- [NIST IR 8596 (Cyber AI Profile)](https://www.bankingnewsai.com/ai-regulation/documents/nist-ir-8596) — Cybersecurity Framework Profile for Artificial Intelligence (Cyber AI Profile), NIST IR 8596 — preliminary draft (Dec 16, 2025)
- [NIST COSAiS control overlays](https://www.bankingnewsai.com/ai-regulation/documents/nist-cosais-control-overlays) — Control Overlays for Securing AI Systems (COSAiS): SP 800-53 overlays for generative, predictive and agentic AI (Aug 14, 2025)
- [NIST AI 600-1 (Generative AI Profile)](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-600-1) — Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1) (Jul 26, 2024)
- [NIST SP 800-218A (SSDF profile for generative AI)](https://www.bankingnewsai.com/ai-regulation/documents/nist-sp-800-218a) — Secure Software Development Practices for Generative AI and Dual-Use Foundation Models: An SSDF Community Profile (NIST SP 800-218A) (Jul 26, 2024)
- [NIST AI RMF 1.0](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-100-1) — Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (Jan 26, 2023)
- [NIST AI RMF Playbook](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-rmf-playbook) — AI Risk Management Framework Playbook (Jan 26, 2023)

Last reviewed Aug 26, 2026. Cite the official text (https://csrc.nist.gov/pubs/ai/100/2/e2025/final) for the rule and this page for the summary and dates.

---

Canonical page: https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-100-2e2025
Part of [BankingNewsAI](https://www.bankingnewsai.com/) — a free daily brief on AI in banking, an AI regulation tracker (41 authorities, 237 documents) and AI-strategy profiles of the 120 largest US banks. Markdown versions of every reference page: append `.md` to the page URL; index at https://www.bankingnewsai.com/llms.txt.
