Standard / soft law
Three MITRE ATLAS mitigations set agent permissions. A privileged agent, or one that serves several users, gets role- or attribute-based access control and only the permissions its task needs (AML.M0026). An agent acting for one user gets that user's delegated access and never more than the user could have, with its identity and access managed until it is decommissioned (AML.M0027). A tool shared by several agents receives the permissions, identity and restrictions of the agent that calls it, set in the MCP server or the tool's own configuration (AML.M0028). They address agent tool invocation (AML.T0053) and exfiltration or data destruction through tools (AML.T0086, AML.T0101). Detect agents granted wildcard tools, unrestricted shell or admin credentials, and tools that call downstream systems with one shared credential instead of the requesting user's. Lifecycle management and decommissioning of per-user agent identities are not detected.
mitre-atlas.agent-and-tool-permissions · MITRE ATLAS 2026.09, AML.M0026 Privileged AI Agent Permissions Configuration (description) · official source · jurisdictions: INTL
The guard to add, and how far to trust this rule
Standard / soft law
MITRE ATLAS mitigation AML.M0033 asks for validation of what flows into and out of the tools and data sources an agent uses: a common data format, schema validation, checks for leaked sensitive or prohibited information, and sanitization that removes injections or unsafe code, performed outside the agent so that a compromise cannot spread along a chain of components. It addresses prompt injection (AML.T0051), agent tool invocation (AML.T0053) and exfiltration through tools (AML.T0086). Detect model or agent output that reaches an interpreter, a shell, a database query, a file path or a renderer with no schema validation, encoding or sandbox.
mitre-atlas.agent-component-input-output-validation · MITRE ATLAS 2026.09, AML.M0033 Input and Output Validation for AI Agent Components (description) · official source · jurisdictions: INTL
The guard to add, and how far to trust this rule
Standard / soft law
MITRE ATLAS mitigation AML.M0035 (AI Red Team) calls for recurring, authorized, threat-informed red-team exercises that find and fix weaknesses in an AI-enabled system before it is deployed and while it runs, repeated as threats evolve and whenever the system, its components, its intended use or its deployment environment change. Its listed techniques run from supply-chain compromise (AML.T0010) to prompt injection, jailbreaks and system-prompt extraction (AML.T0051, AML.T0054, AML.T0056) and RAG and memory poisoning (AML.T0070, AML.T0080). Detect fine-tuned or adapted models, added retrieval, and new third-party models with no evaluation or red-team run wired to the change.
mitre-atlas.ai-red-team · MITRE ATLAS 2026.09, AML.M0035 AI Red Team (description, paragraph 1) · official source · jurisdictions: INTL
The guard to add, and how far to trust this rule
Standard / soft law
MITRE ATLAS mitigation AML.M0024 (AI Telemetry Logging) asks deployers to log what goes into and comes out of deployed models and, for agents, each intermediate step: the actions and decisions taken, the data accessed and tools used, any installation commands and the agent's identity, so that monitoring can catch attacks such as prompt injection (AML.T0051), exfiltration through the inference API (AML.T0024) or through agent tool calls (AML.T0086). Detect repositories that call models or run agents with no AI tracing or audit instrumentation.
mitre-atlas.ai-telemetry-logging · MITRE ATLAS 2026.09, AML.M0024 AI Telemetry Logging (description) · official source · jurisdictions: INTL
The guard to add, and how far to trust this rule
Standard / soft law
MITRE ATLAS mitigation AML.M0037 fixes an agent's maximum authority before it runs, treats resources, identities and targets the agent discovers while running as out of scope until they are validated and added, enforces this outside the agent rather than through its prompt or alignment, and passes the original limits down to sub-agents, which may get narrower limits but never broader ones. AML.M0038 checks throughout a run whether the agent's planned actions still serve its authorized objective, and pauses, restricts tools, asks for approval, returns to the authorized plan or ends the task when they drift. Both address autonomous reconnaissance, attack-path adaptation and attack orchestration (AML.T0116, AML.T0117, AML.T0124). Detect agent deployments with no behavioral monitoring or automatic halt, and tools the model can call that add to the agent's own allowed domains, hosts, tools or scopes.
mitre-atlas.authority-expansion-and-scope-drift · MITRE ATLAS 2026.09, AML.M0037 AI Agent Authority Expansion Controls (description, paragraphs 1 and 2) · official source · jurisdictions: INTL
The guard to add, and how far to trust this rule
Standard / soft law
MITRE ATLAS mitigation AML.M0029 (Human In-the-Loop for AI Agent Actions) has the user or another person approve an agent's actions before it takes them, with a human making the final decision even when audit agents help, and scales the approval to the consequence: little oversight for minor, repetitive tasks with basic tools, approval by several stakeholders for actions with significant consequences. It addresses agent tool invocation (AML.T0053) and exfiltration or data destruction through tools (AML.T0086, AML.T0101). Detect tool calls with side effects that run with no approval step, agent runtimes configured to skip approval, and approval prompts that do not show the exact action.
mitre-atlas.human-in-the-loop-for-agent-actions · MITRE ATLAS 2026.09, AML.M0029 Human In-the-Loop for AI Agent Actions (description) · official source · jurisdictions: INTL
The guard to add, and how far to trust this rule
Standard / soft law
MITRE ATLAS mitigation AML.M0036 bounds what one request, inference job or agent workflow can consume: input, batch and output size, execution time, memory, compute and context and output tokens, and for agents the number of iterations, retries, tool calls, parallel tasks, the delegation depth and downstream spend, applied across the whole workflow with timeouts, cost ceilings, circuit breakers and safe termination. It addresses denial of AI service (AML.T0029) and cost harvesting (AML.T0034). Detect agent loops with no step bound, unbounded parallel fan-out of model-chosen calls, model keys with no spend or output-token caps, and user input sent to a model with no size check.
mitre-atlas.limit-workload-resource-consumption · MITRE ATLAS 2026.09, AML.M0036 Limit AI Workload Resource Consumption (description) · official source · jurisdictions: INTL
The guard to add, and how far to trust this rule
Standard / soft law
MITRE ATLAS mitigation AML.M0031 (Memory Hardening) treats an agent's persistent state, such as saved preferences, memories, conversation summaries and stored history, as something to protect over its whole lifecycle, separately from content guardrails: memory operations are authenticated and authorized within the right user, tenant, agent and session; memory size and update rate are limited and integrity is validated; the source of every update is recorded and known good versions are kept, so suspicious records can be quarantined or rolled back; and security-relevant reads and writes are audited. It addresses context poisoning through memory (AML.T0080.000). Detect memory-write tools the model can call in a turn with untrusted content and no confirmation or provenance gate, and memory items with no source, expiry or user-visible deletion.
mitre-atlas.memory-hardening · MITRE ATLAS 2026.09, AML.M0031 Memory Hardening (description, paragraph 1) · official source · jurisdictions: INTL
The guard to add, and how far to trust this rule
Standard / soft law
MITRE ATLAS mitigation AML.M0030 warns that untrusted data in a model's context can carry prompt injections that make the agent call its tools, and recommends restricting tool invocation once such data is present: block automatic tool calls or ask the user to confirm them, and always confirm high-consequence actions. It addresses agent tool invocation (AML.T0053) and exfiltration or data destruction through tools (AML.T0086, AML.T0101). Detect retrieved or external content that is concatenated into the instruction channel or that directly sets the arguments of a tool call.
mitre-atlas.restrict-tool-invocation-on-untrusted-data · MITRE ATLAS 2026.09, AML.M0030 Restrict AI Agent Tool Invocation on Untrusted Data (description) · official source · jurisdictions: INTL
The guard to add, and how far to trust this rule