# Threat-model an AI development workflow

Taiga Learning · Worksheet
https://taiga.training/en/lessons/threat-modeling/

Use fictional or approved information. Do not put secrets in this worksheet.

## Learning objectives
- Draw the development system beyond the application itself.
- Describe a concrete threat with an actor, action, and consequence.
- Convert a threat into an owned control and verification step.

## Exercise
Open the risk-review exercise. Select internal data, branch writes, external users, and difficult recovery. Choose one resulting concern. Write the actor, entry point, affected asset, consequence, control, denial test, owner, and review trigger.

## Your response
- Scenario and scope:
- Assumptions and open questions:
- Proposed answer or decision, with reasons:

## Verify your response
| Claim or criterion | Evidence or test | Result or gap | Owner |
| --- | --- | --- | --- |
| | | | |
| | | | |
| | | | |

## Next action
- Action, owner, and date:
- When will you review this response?

## Principle to retain
A useful threat model connects a specific failure path to a control, a test, and an owner. Keep it current as the workflow changes.

## Sources
- [OWASP: Threat Modeling](https://cheatsheetseries.owasp.org/cheatsheets/Threat_Modeling_Cheat_Sheet.html)
- [NIST: AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework)

This worksheet supports learning. Completing it does not itself authorize a production change.
