Book an Appointment

MAESTRO: Threat Modeling for Agentic AI

How to systematically identify, assess and treat threats in systems of autonomous AI agents using the Cloud Security Alliance's seven-layer framework.

Last updated: July 2026 · Valeri Milke, ISO 27001 & ISO 42001 Lead Auditor

7layers in the MAESTRO reference architecture
6steps in the CSA process — incl. cross-layer analysis
17agentic threats in the OWASP catalog (T1–T17)
3classic methods with gaps: STRIDE, PASTA, LINDDUN

AI agents that plan autonomously, invoke tools and cooperate with other agents fundamentally change the attack surface: threats no longer arise only in code, but in the agents' goals, memory and interactions. Classic threat modeling methods such as STRIDE or PASTA were designed for deterministic software and capture this dynamic only incompletely. That is why, in early February 2025, the Cloud Security Alliance published MAESTRO, a dedicated threat modeling framework for agentic AI that decomposes systems into seven architectural layers and analyzes threats both layer by layer and across layers. Combined with the OWASP catalog of agentic threats, this yields a practical approach for security leaders.

From blog post to applied method

The 2025 milestones of MAESTRO and the OWASP catalog — tap a milestone for details.

The Essentials at a Glance

Six topic blocks — tap to expand.

Why STRIDE, PASTA and LINDDUN are not enough

According to the CSA's rationale, each of the three established methods leaves key agentic threats open — and none systematically captures unpredictable agent behavior, goal misalignment, collusion between agents or AI supply chain risks. These are exactly the gaps MAESTRO is built to close.

Gap: AI-specific threats
  • Models software with predictable behavior — it lacks a view of AI-specific threats such as adversarial attacks.
  • The unpredictable learning and decision-making behavior of agents also goes uncaptured.
Adversarial attacksLearning and decision-making behavior

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

Cloud Security Alliance · 2025

Agentic AI Threat Modeling Framework: MAESTRO

Original publication by Ken Huang (February 6, 2025) with the acronym, the seven-layer reference architecture and the six-step approach including cross-layer threats.

OWASP GenAI Security Project / Agentic Security Initiative · 2025

Agentic AI – Threats and Mitigations, Version 1.1

Catalog of 17 agentic threats (T1–T17) with a taxonomy navigator (as of December 2025); references MAESTRO as a layer-based STRIDE extension for agentic AI.

Cloud Security Alliance · 2025

Threat Modeling Google's A2A Protocol with the MAESTRO Framework

Worked example by Ken Huang and Idan Habler (April 30, 2025): a complete MAESTRO analysis of an agent-to-agent protocol with layer-specific threats.

Cloud Security Alliance · 2025

Agentic AI Red Teaming Guide

Complementary CSA guide (May 28, 2025) for hands-on testing of agentic systems, covering among other things permission escalation, memory manipulation and orchestration failures.

Agentic AI in production – is your threat landscape under control?

We model your agent architecture along the MAESTRO layers and prioritize risks and mitigations together with you. Contact us for a no-obligation initial consultation.