Skip to content
← home
The Tool, Target, Threat AI-security taxonomy: one faceted AI core seen three ways — gripped as a tool, marked by a crosshair as a target, and shearing apart as an autonomous threat.

Tool, Target, Threat

Tool / Target / Threat (TTT) is a three-orientation taxonomy for AI security: AI as a Tool — humans using AI to accelerate existing capabilities; AI as a Target — AI systems as the object of attack or defense; and AI as a Threat — AI operating as an autonomous or semi-autonomous actor. I built it in early 2023, and it has since become common language across industry and policy.

The first question in any AI security conversation should be: tool, target, or threat? They're lenses, not bins — real incidents usually span more than one.

The three orientations

AI as a Tool

A force multiplier. Compresses the OODA loop for whoever wields it. Doesn't change what is happening — changes the speed, scale, and cost. The human sets the tasking.

AI as a Target

The AI itself is the thing being compromised. Prompt injection, training-data poisoning, model extraction, ML supply-chain attacks, agent exploitation — an attack surface traditional testing wasn't built for. Safety alignment is not security.

AI as a Threat

AI operating as an autonomous or semi-autonomous actor. The cleanest line between tool and threat: who sets the tasking.

Origin

I developed the taxonomy in early 2023 while working with the ONCD on what became EO 14110 — every "AI security" conversation was breaking down because nobody meant the same thing by it. The full story, with case studies: AI security: Tool, Target, Threat.

How to cite

Ellis, C. (2023). AI Security: Tool, Target, Threat. https://cje.io/ttt/

Short form: "the Tool/Target/Threat taxonomy (Ellis, 2023)".

Provenance & adoption

A dated record of the taxonomy's origin and spread — verified public sources only:

  • Early 2023 — developed during ONCD / EO 14110 policy work. No competing origin claim or prior art for the triad exists in the public record.
  • 5 Apr 2024 — canonical essay: AI security: Tool, Target, Threat — "The first question in any AI security conversation should be: tool, target, or threat?"
  • Apr 2024 — the framing enters industry reference material, structured as "AI will come to play three significant roles: tool, target, and threat."
  • May 2024 (RSA Conference) — on-camera: "There's AI as a tool… AI as a target… AI as a threat."
  • Oct 2024 — a major annual hacker-community research report is organized entirely around AI "as a tool, a target, and a threat."
  • 2025–2026 — the tool / target / threat framing appears widely across vendor writing, press, and policy — often without attribution. If you're using it, a citation is appreciated.

Using the taxonomy in your own work? Attribution appreciated — and tell me where it shows up.