If you have ever worked with MITRE ATT&CK, you already know the shape of the thing: a structured, community-maintained catalog of how real attackers behave, organized so that defenders can talk about threats with a common vocabulary. MITRE ATLAS is the same idea pointed at AI systems. And as of its early-2026 updates, it now describes attacks that specifically target autonomous agents — the tools they call, and the supply chains they pull those tools from.
What ATLAS actually is
ATLAS stands for Adversarial Threat Landscape for Artificial-Intelligence Systems. It is a knowledge base of adversary tactics, techniques, and procedures aimed at AI and machine-learning systems, structured the same way ATT&CK structures threats to traditional IT.
The hierarchy is worth internalizing because it tells you how to read the thing:
Tactics are the attacker's goals — why they are doing something (Initial Access, Resource Development, Exfiltration, and so on).











