What MITRE ATLAS Prompt Infiltration via Public-Facing Application (AML.T0093) - Adversarial Prompt Infiltration via Public-Facing Application threat to AI systems requires
This node addresses MITRE ATLAS technique AML.T0093 (Prompt Infiltration via Public-Facing Application). An adversary may introduce malicious prompts into the victim's system via a public-facing application with the intention of it being ingested by an AI at some point in the future and ultimately having a downstream effect. This may occur when a data source is indexed by a retrieval augmented generation (RAG) system, when a rule triggers an action by an AI agent, or when a user utilizes a large language model (LLM) to interact with the malicious content. The malicious prompts may persist on the victim system for an extended period and could affect multiple users and various AI tools within the victim organization. Any public-facing application that accepts text input could be a target. This includes email, shared document systems like OneDrive or Google Drive, and service desks or ticketing ... Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.
Pillar: AI Governance & Law · Authority: MITRE Corporation · Version: 1.0.1 · Last updated:
Primary source: https://raw.githubusercontent.com/mitre-atlas/atlas-data/main/dist/ATLAS.yaml
SHA-256 integrity: 01f3e54c029964b795575c0603c910ee3dba0d94753164d4a6cf8c469db6e987
Primary Citations — 7 traced to source
- MITRE ATLAS - Prompt Infiltration via Public-Facing Application (AML.T0093), https://raw.githubusercontent.com/mitre-atlas/atlas-data/main/dist/ATLAS.yaml#AML.T0093, AML.T0093 technique entry, 2026
- EU AI Act - Regulation (EU) 2024/1689 on Artificial Intelligence, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689, Article 15 (Accuracy, Robustness, Cybersecurity), 2024
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-atlas-prompt-infiltration-via-public-facing-application.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-atlas-prompt-infiltration-via-public-facing-application.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-atlas-prompt-infiltration-via-public-facing-application
- Back to registry: Browse all 10,099 compliance nodes