Tool, Target, Threat
Tool / Target / Threat (TTT) is a three-orientation taxonomy for AI security: AI as a Tool — humans using AI to accelerate existing capabilities; AI as a Target — AI systems as the object of attack or defense; and AI as a Threat — AI operating as an autonomous or semi-autonomous actor. I built it in early 2023, and it has since become common language across industry and policy.
The first question in any AI security conversation should be: tool, target, or threat? They're lenses, not bins — real incidents usually span more than one.
The three orientations
AI as a Tool
A force multiplier. Compresses the OODA loop for whoever wields it. Doesn't change what is happening — changes the speed, scale, and cost. The human sets the tasking.
AI as a Target
The AI itself is the thing being compromised. Prompt injection, training-data poisoning, model extraction, ML supply-chain attacks, agent exploitation — an attack surface traditional testing wasn't built for. Safety alignment is not security.
AI as a Threat
AI operating as an autonomous or semi-autonomous actor. The cleanest line between tool and threat: who sets the tasking.
Origin
I developed the taxonomy in early 2023 while working with the ONCD on what became EO 14110 — every "AI security" conversation was breaking down because nobody meant the same thing by it. The full story, with case studies: AI security: Tool, Target, Threat.
How to cite
Ellis, C. (2023). AI Security: Tool, Target, Threat. https://cje.io/ttt/
Short form: "the Tool/Target/Threat taxonomy (Ellis, 2023)".
Provenance & adoption
A dated record of the taxonomy's origin and spread — verified public sources only:
- Early 2023 — developed during ONCD / EO 14110 policy work. No competing origin claim or prior art for the triad exists in the public record.
- 5 Apr 2024 — canonical essay: AI security: Tool, Target, Threat — "The first question in any AI security conversation should be: tool, target, or threat?"
- Apr 2024 — the framing enters industry reference material, structured as "AI will come to play three significant roles: tool, target, and threat."
- May 2024 (RSA Conference) — on-camera: "There's AI as a tool… AI as a target… AI as a threat."
- Oct 2024 — a major annual hacker-community research report is organized entirely around AI "as a tool, a target, and a threat."
- 2025–2026 — the tool / target / threat framing appears widely across vendor writing, press, and policy — often without attribution. If you're using it, a citation is appreciated.
Using the taxonomy in your own work? Attribution appreciated — and tell me where it shows up.