Elevation of Autonomy for Threat Modelling AI Systems
Description
Description
Elevation of Autonomy is a card-based threat-modelling deck designed to help teams identify security, privacy and architectural risks in systems that use AI, large language models and autonomous agents.
Rather than working through another checklist, your team applies each threat directly to the system you are building. The cards provide prompts for discussion, helping engineers uncover risks, challenge assumptions and decide where stronger controls are needed.
The deck extends the card-based threat-modelling approach of Elevation of Privilege into the AI and agentic systems space.
Who is it for?
Who is it for?
Elevation of Autonomy is particularly suited to teams designing, building or reviewing systems involving:
LLM applications · AI assistants · RAG systems · AI-enabled SaaS products · autonomous agents · MCP integrations · AI development tools · multi-agent systems
Bulk Pricing
Bulk Pricing
Automatically applied at checkout:
| Buy | Discount |
|---|---|
| 5 or more decks | 5% off |
| 10 or more decks | 10% off |
| 20 or more decks | 15% off |
| 30 or more decks | 20% off |
Specifications
Specifications
-
SuitsAdversarial Threats, Autonomy Threats, Data Threats, Privacy Threats, Structural Hazards
-
# Cards
-
Created by
Try a branded version
If you'd like to encourage the use of this technique within your team or organisation, a branded deck is a great way to demonstrate your support and commitment to the process.
What is Elevation of Autonomy?
AI systems introduce a different set of security questions.
What happens when a model follows instructions hidden inside retrieved content? What if an agent has more permissions than it needs? Can memory be poisoned? Could a tool description itself become an attack vector? What happens when your application trusts a model output that is confidently wrong?
Elevation of Autonomy turns those questions into a structured team exercise.
The deck contains threats covering five areas:
- Adversarial Threats: attacks directed at models and agents, including prompt injection, tool misuse and supply-chain compromise.
- Autonomy Threats: risks created when AI systems are allowed to take actions or make decisions.
- Data Threats: risks involving training data, retrieved information, vector stores, outputs and resource consumption.
- Privacy Threats: privacy risks informed by frameworks including LINDDUN and T.R.I.M.
- Structural Hazards: deeper architectural and mathematical risks that cannot simply be solved by improving the model itself.
The threats are deliberately designed to remain useful as individual models, vendors and technology stacks change. Supporting examples and mitigations can evolve without changing the underlying threat categories.

How the game works?
Played like EoP: each player gets a hand, leads a suit, others follow with applicable threats against the system being modelled, highest card wins the trick, tricks convert into recorded threats in the post-session template.
The goal is not winning the game but surfacing threats the team would otherwise miss.

