MITRE ATLAS Mapped 2026 Top AI Agent Security Detection – Exfiltration via AI Agent Tool Invocation (AML.T0086)

Detects an AI agent session that performs a data exfiltration action (e.g., sending an email, webhook, or file share) to an unauthorized or non-allowlisted destination shortly after the agent has ingested potentially untrusted external content. This behavior is indicative of an AI agent being manipulated to exfiltrate data after processing malicious or adversarial inputs.