Appendix N — AI Attack and Deception Mitigation Checklist
This checklist provides a practical tool for organizations to identify, prevent, and mitigate AI attacks and deception behaviors. It addresses the risks of autonomous AI agents engaging in deceptive, manipulative, or harmful actions—including identity fabrication, social engineering, supply chain attacks, multi-agent coordination, and evidence concealment.
Instructions: For each item, assess your organization’s current mitigation status using the following scale:
✅ Implemented — Fully implemented and operational
⚠️ Partial — Partially implemented or in progress
❌ Not Started — Not yet implemented or not started
N/A — Not applicable to your organization
N.1 Identity and Deception Mitigation
Section N.1.1: Identity Fabrication Prevention
#
Mitigation Item
Implemented
Partial
Not Started
N/A
Notes
1.1.1
Are AI agents prevented from creating fake or synthetic identities?
☐
☐
☐
☐
1.1.2
Are there controls preventing AI agents from impersonating real individuals?
☐
☐
☐
☐
1.1.3
Are AI agent accounts subject to verification and authentication?
☐
☐
☐
☐
1.1.4
Is there monitoring for unauthorized account creation by AI agents?
☐
☐
☐
☐
1.1.5
Are there processes to detect and remove fake accounts created by AI agents?
☐
☐
☐
☐
Section N.1.2: Social Engineering Prevention
#
Mitigation Item
Implemented
Partial
Not Started
N/A
Notes
1.2.1
Are AI agents prevented from engaging in social engineering attacks?
☐
☐
☐
☐
1.2.2
Is there monitoring for AI agent attempts to manipulate humans?
☐
☐
☐
☐
1.2.3
Are there safeguards against AI agents sending spear-phishing messages?
☐
☐
☐
☐
1.2.4
Is there employee training on identifying AI-driven social engineering?
☐
☐
☐
☐
1.2.5
Are there reporting mechanisms for suspected AI social engineering attempts?
☐
☐
☐
☐
Section N.1.3: Evidence Concealment Prevention
#
Mitigation Item
Implemented
Partial
Not Started
N/A
Notes
1.3.1
Are AI agents prevented from modifying or deleting records to hide actions?
☐
☐
☐
☐
1.3.2
Is there immutable logging of all AI agent actions?
☐
☐
☐
☐
1.3.3
Are audit trails maintained and protected from tampering?
☐
☐
☐
☐
1.3.4
Is there monitoring for suspicious modification of records?
☐
☐
☐
☐
1.3.5
Are there processes to investigate and recover tampered records?
☐
☐
☐
☐
N.2 Attack Prevention and Detection
Section N.2.1: Supply Chain Attack Prevention
#
Mitigation Item
Implemented
Partial
Not Started
N/A
Notes
2.1.1
Are AI agents prevented from submitting malicious code to repositories?
☐
☐
☐
☐
2.1.2
Is there code review for all submissions, including from AI agents?
☐
☐
☐
☐
2.1.3
Are there automated security scans for malicious code?
☐
☐
☐
☐
2.1.4
Is there monitoring for supply chain attacks targeting open-source projects?
☐
☐
☐
☐
2.1.5
Are there processes to respond to suspected supply chain attacks?
☐
☐
☐
☐
Section N.2.2: Prompt Injection Prevention
#
Mitigation Item
Implemented
Partial
Not Started
N/A
Notes
2.2.1
Are AI agents protected against prompt injection attacks?
☐
☐
☐
☐
2.2.2
Is there input validation and sanitization for AI agent prompts?
☐
☐
☐
☐
2.2.3
Are there safeguards to prevent AI agents from executing injected instructions?
☐
☐
☐
☐
2.2.4
Is there monitoring for prompt injection attempts targeting AI agents?
☐
☐
☐
☐
2.2.5
Are there processes to respond to successful prompt injection incidents?
☐
☐
☐
☐
Section N.2.3: Multi-Agent Coordination Detection
#
Mitigation Item
Implemented
Partial
Not Started
N/A
Notes
2.3.1
Is there monitoring for unauthorized communication between AI agents?
☐
☐
☐
☐
2.3.2
Are AI agents prevented from sharing credentials or access tokens?
☐
☐
☐
☐
2.3.3
Is there detection for AI agents creating shared resources or channels?
☐
☐
☐
☐
2.3.4
Are there controls preventing AI agents from collaborating on attacks?
☐
☐
☐
☐
2.3.5
Is there monitoring for multi-agent collusion patterns?
☐
☐
☐
☐
N.3 Action Boundary and Access Control
Section N.3.1: Action Boundary Enforcement
#
Mitigation Item
Implemented
Partial
Not Started
N/A
Notes
3.1.1
Are clear boundaries defined for AI agent actions?
☐
☐
☐
☐
3.1.2
Is there technical enforcement of action boundaries?
☐
☐
☐
☐
3.1.3
Are AI agents prevented from taking actions outside their authorized scope?
☐
☐
☐
☐
3.1.4
Is there monitoring for boundary violations?
☐
☐
☐
☐
3.1.5
Are there processes to respond to boundary violations?
☐
☐
☐
☐
Section N.3.2: Access Control
#
Mitigation Item
Implemented
Partial
Not Started
N/A
Notes
3.2.1
Is there least-privilege access control for AI agents?
☐
☐
☐
☐
3.2.2
Are AI agents prevented from escalating their own privileges?
☐
☐
☐
☐
3.2.3
Is there monitoring for unauthorized access attempts?
☐
☐
☐
☐
3.2.4
Are access tokens and credentials protected from AI agent misuse?
☐
☐
☐
☐
3.2.5
Are there processes to revoke access for compromised AI agents?
☐
☐
☐
☐
N.4 Monitoring and Detection
Section N.4.1: Behavioral Monitoring
#
Mitigation Item
Implemented
Partial
Not Started
N/A
Notes
4.1.1
Is there continuous monitoring of AI agent behavior?
☐
☐
☐
☐
4.1.2
Are there baseline behavioral patterns established for AI agents?
☐
☐
☐
☐
4.1.3
Is there detection for anomalous behavior patterns?
☐
☐
☐
☐
4.1.4
Are there automated alerts for suspicious behavior?
☐
☐
☐
☐
4.1.5
Is there real-time analysis of AI agent actions?
☐
☐
☐
☐
Section N.4.2: Communication Monitoring
#
Mitigation Item
Implemented
Partial
Not Started
N/A
Notes
4.2.1
Is there monitoring of AI agent communications?
☐
☐
☐
☐
4.2.2
Is there detection for unauthorized agent-to-agent communication?
☐
☐
☐
☐
4.2.3
Are communication patterns analyzed for coordination signals?
☐
☐
☐
☐
4.2.4
Is there monitoring of AI agent interactions with external systems?
☐
☐
☐
☐
4.2.5
Are there processes to investigate suspicious communications?
☐
☐
☐
☐
Section N.4.3: Anomaly Detection
#
Mitigation Item
Implemented
Partial
Not Started
N/A
Notes
4.3.1
Is there ML-based anomaly detection for AI agent behavior?
☐
☐
☐
☐
4.3.2
Are statistical baselines established for normal behavior?
☐
☐
☐
☐
4.3.3
Is there detection for anomalies in decision patterns?
☐
☐
☐
☐
4.3.4
Are there processes to investigate and respond to anomalies?
☐
☐
☐
☐
4.3.5
Is the anomaly detection system regularly updated?
☐
☐
☐
☐
N.5 Incident Response and Recovery
Section N.5.1: Incident Detection
#
Mitigation Item
Implemented
Partial
Not Started
N/A
Notes
5.1.1
Is there a process for detecting AI attack and deception incidents?
☐
☐
☐
☐
5.1.2
Are there clear criteria for identifying AI incidents?
☐
☐
☐
☐
5.1.3
Is there automated alerting for potential incidents?
☐
☐
☐
☐
5.1.4
Are there processes for human review of incident alerts?
☐
☐
☐
☐
5.1.5
Is there incident classification and prioritization?
☐
☐
☐
☐
Section N.5.2: Incident Response
#
Mitigation Item
Implemented
Partial
Not Started
N/A
Notes
5.2.1
Is there a documented incident response plan for AI attacks?
☐
☐
☐
☐
5.2.2
Are incident response teams identified and trained?
☐
☐
☐
☐
5.2.3
Is there a process for containing and isolating compromised AI agents?
☐
☐
☐
☐
5.2.4
Are there procedures for evidence collection and preservation?
☐
☐
☐
☐
5.2.5
Is there a process for notifying affected parties?
☐
☐
☐
☐
Section N.5.3: Recovery and Lessons Learned
#
Mitigation Item
Implemented
Partial
Not Started
N/A
Notes
5.3.1
Is there a process for restoring compromised AI systems?
☐
☐
☐
☐
5.3.2
Is there a process for conducting post-incident reviews?
☐
☐
☐
☐
5.3.3
Are lessons learned documented and incorporated?
☐
☐
☐
☐
5.3.4
Is there a process for updating controls based on incidents?
☐
☐
☐
☐
5.3.5
Is there a process for sharing lessons learned with the community?
☐
☐
☐
☐
N.6 Governance and Accountability
Section N.6.1: Governance Structure
#
Mitigation Item
Implemented
Partial
Not Started
N/A
Notes
6.1.1
Is there clear accountability for AI attack and deception mitigation?
☐
☐
☐
☐
6.1.2
Are roles and responsibilities for AI security clearly defined?
☐
☐
☐
☐
6.1.3
Is there an AI security or governance committee?
☐
☐
☐
☐
6.1.4
Are there policies specifically addressing AI deception risks?
☐
☐
☐
☐
6.1.5
Is governance reviewed and updated regularly?
☐
☐
☐
☐
Section N.6.2: Compliance and Oversight
#
Mitigation Item
Implemented
Partial
Not Started
N/A
Notes
6.2.1
Is compliance with mitigation requirements monitored?
☐
☐
☐
☐
6.2.2
Are there regular audits of AI attack and deception controls?
☐
☐
☐
☐
6.2.3
Are audit findings addressed in a timely manner?
☐
☐
☐
☐
6.2.4
Is there a process for reporting mitigation status to leadership?
☐
☐
☐
☐
6.2.5
Is there independent oversight of AI security practices?