{
  "node_id": "mitre-atlas-ai-model-inference-api-access",
  "title": "MITRE ATLAS AI Model Inference API Access (AML.T0040) - AI Model Access adversarial technique against AI systems",
  "domain": "AI Governance & Law",
  "version": "1.0.1",
  "last_updated": "2026-07-22",
  "bluf": "This node addresses MITRE ATLAS technique AML.T0040 (AI Model Inference API Access), an adversarial technique in the ATLAS AI Model Access tactic. Adversaries may gain access to a model via legitimate access to the inference API. Inference API access can be a source of information to the adversary (discover model ontology, discover model family), a means of staging the attack (verify attack, craft adv), or for introducing data to the target system for Impact (evade model, erode integrity). Many systems rely on the same models provided via an inference API, which means they share the same vulnerabilities. This is especially true of foundation models which are prohibitively resource intensive to train. Adversaries may use their access to model APIs to identify vulnerabilities such as jailbreaks or hallucinations and then target applications that use the same models. Defending against this technique is required under EU AI Act (accuracy, robustness and cybersecurity), NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "ai_overlay_2026"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-ai-rmf-1-0",
    "eu-ai-act-2024",
    "iso-iec-42001-ai-management-system-2023",
    "owasp-agentic-top10"
  ],
  "primary_citations_count": 7
}