AML-ATLAS-2026-19 | MITRE ATLAS Mapped 2026 – Top AI Threat Detection: AI API Key and Valid Account Abuse (AML.T0012)

This rule monitors for suspicious activity related to AI service accounts and API keys. It detects potential account or key compromise by identifying impossible travel sign-ins coupled with AI API usage, simultaneous usage of a single API key from multiple disjoint network locations, and sudden, high-volume activity from previously dormant service account API keys.