# Agentic AI Threat Model Builder — Free Tool > Pick an industry, switch components on or off, get a full STRIDE threat register mapped to four OWASP frameworks — editable, exportable as PDF. URL: [https://playciso.com/tools/ai-threat-model](https://playciso.com/tools/ai-threat-model) The Agentic AI Threat Model Builder turns a generic, vendor-neutral threat model for AI systems into something you can apply to your own architecture in minutes. It models the ten components almost every LLM or agent deployment has — user channel, edge gateway, identity provider, agent runtime, model endpoint, tool-execution layer (including MCP servers), enterprise APIs, session and memory store, RAG knowledge index, and human handoff — and the trust boundaries between them. Switch off the components you do not run and the boundaries (and their threats) disappear; switch them on and they come back. Every threat is classified by STRIDE, cross-referenced to the OWASP Agentic AI, LLM, MCP and AppSec Top 10s, and ships with a plain-language attack scenario and a list of controls. Six industry profiles (retail, financial services, healthcare, government, SaaS, critical infrastructure) raise the impact of the threats that matter most in that sector and add regulatory context to the report. Everything is editable in place — titles, scenarios, likelihood and impact ratings, treatment status, owners, notes and controls — and you can add threats of your own. The model autosaves in your browser, can be exported and re-imported as JSON, and exports as a full PDF report with a risk summary, the register and a STRIDE × framework matrix. ## How to use it - Choose the industry profile that matches the system (or leave it unset for neutral weighting). - On the architecture canvas, click components to include or exclude them. Trust boundaries appear only when both ends are in scope; click a boundary label to jump to its threats. - Work through the threat register: re-rate likelihood and impact, set a status and owner, edit the scenario and controls, untick threats that do not apply, or add your own. - Read the risk picture — heatmap, STRIDE spread, top risks and the STRIDE × OWASP matrix — then export the PDF or save the JSON to continue later. ## FAQ ### Is this a real threat model or just a checklist? It is a real threat model in the STRIDE-per-trust-boundary style: threats are attached to the specific boundary they cross (for example "agent runtime to tool-execution layer"), each with an attack scenario, a likelihood × impact rating and controls. What makes it reusable is that the catalogue is vendor- and company-neutral, so you tailor it by scoping components and editing, rather than starting from a blank page. ### Which frameworks does it map to? Every catalogued threat is cross-referenced to the OWASP Top 10 for Agentic Applications (2026, ASI01–ASI10), the OWASP Top 10 for LLM Applications (2025, LLM01–LLM10), the OWASP MCP Top 10 (2025, MCP01–MCP10) and the OWASP Top 10 for web applications (2025, A01–A10). The risk-picture section aggregates these into a STRIDE × framework matrix, and the PDF includes the same matrix. ### How is risk scored? Likelihood and impact are each rated 1–5 and multiplied (maximum 25). Bands are Low 1–4, Medium 5–9, High 10–15 and Critical 16–25. Choosing an industry profile raises impact by one point (capped at 5) for threats that touch the data or outcomes that sector is most exposed on — for example personal data in healthcare or fraud in financial services. Any rating you set by hand overrides the default. ### Does my architecture or threat model get uploaded anywhere? No. The tool runs entirely in your browser. The model is autosaved to your browser's local storage, and the PDF and JSON exports are generated on your device. Nothing is sent to a server. ### Can I use this for a chatbot, a copilot or a RAG search? Yes — the ten components cover all three. A RAG search would keep the knowledge index and ingestion boundaries in scope; a copilot with write access would keep the tool-execution layer and enterprise APIs; a simple assistant might switch off RAG and human handoff entirely. The register adapts to whatever you leave switched on. --- PlayCISO is a simulation-first platform for security leaders: a War Room incident simulator, a simulated PCI DSS QSA interview, board-report coaching, free security scanners, and a curated library of free courses. https://playciso.com