MITRE ATLAS 2026.09 / technique reference
AML.T0086
Exfiltration via AI Agent Tool Invocation
MITRE source definition
AI agent tools capable of performing write operations may be invoked to exfiltrate data to an adversary. Sensitive information can be encoded into the tool's input parameters and transmitted to an adversary-controlled location (such as an inbox, document, or server) as part of a seemingly legitimate action. Variants include sending emails, creating or modifying documents, updating CRM records, or even generating media such as images or videos.
The invoked tool itself may be legitimate but invoked by an adversary via [LLM Prompt Injection](/techniques/AML.T0051), or the tool may be malicious (See [AI Agent Tool Poisoning](/techniques/AML.T0110)).
[AI Agent Tool Poisoning](/techniques/AML.T0110) can also be used to manipulate the inputs and destination of a separate legitimate tool, invoked through normal usage by the victim.
Source modified 2026-05-27. Reproduced from the pinned ATLAS release; inline technique links resolve to local reference pages.
Parent, sub-techniques and ATT&CK references
No explicit relationship in this pinned source.
Source-backed defensive context
MITRE mitigations
- AML.M0024 AI Telemetry Logging
- AML.M0026 Privileged AI Agent Permissions Configuration
- AML.M0027 Single-User AI Agent Permissions Configuration
- AML.M0028 AI Agent Tools Permissions Configuration
- AML.M0029 Human In-the-Loop for AI Agent Actions
- AML.M0030 Restrict AI Agent Tool Invocation on Untrusted Data
- AML.M0032 Segmentation of AI Agent Components
- AML.M0033 Input and Output Validation for AI Agent Components
MITRE case studies
- AML.CS0037 Data Exfiltration via Agent Tools in Copilot Studio · Exercise
- AML.CS0039 Living Off AI: Prompt Injection via Jira Service Management · Exercise
- AML.CS0045 Data Exfiltration via an MCP Server used by Cursor · Exercise
- AML.CS0053 Poisoned Postmark MCP Server Email Exfiltration · Incident
- AML.CS0054 Data Exfiltration via Remote Poisoned MCP Tool · Exercise
- AML.CS0061 AI in the Middle: Web-Based AI Services as C2 Relays · Exercise
- AML.CS0063 Prompt-Based Attacks Against Gemini via Calendar Invitations · Exercise
- AML.CS0064 Poisoned GGUF Templates: Inference-Time Supply Chain Attack · Exercise
- AML.CS0066 ZombieAgent: Data Exfiltration Attack on ChatGPT · Exercise
- AML.CS0067 Claude Code GitHub Action Secret Exposure · Exercise
These are explicit source relationships, not independently reproduced incidents or validated detection coverage.
Simulation and telemetry boundary
This is a technique reference page, not a runnable simulation. No ATLAS-specific telemetry mapping, local attack execution or detector validation is asserted. MITRE maturity describes its source evidence, not a 1200km lab result.
For broader context—not technique-specific control mappings—see AI Security, AI Security Course, and detection-validation methodology.
Provenance and attribution
Immutable MITRE ATLAS source · Import provenance · Attribution and transformation notice · Apache License 2.0
Copyright 2021-2026 MITRE. Source text and explicit relationships are retained; navigation, formatting and local links are provided by 1200km.
No explicit relationship in this pinned source.