M ManySignal

Attack Surface: AI Infrastructure

AI attack surface

Your organization deployed 14 AI assistants, 3 autonomous agents, and 40 MCP servers last quarter. Security has visibility into zero of them. ManySignal monitors the AI layer traditional tools can't see.

Attack surface map

The AI attack surface is growing faster than security can see

LLM API calls

T1567

Data leakage via AI prompt payloads, PII in API requests

AI agent tool invocations

T1059

Scope creep beyond intended agent permissions

MCP server connections

T1195

Compromised tool servers altering agent behavior

AI service accounts

T1078.004

Over-privileged OAuth grants, stale API keys

Training data access

T1213

Data poisoning, sensitive data in training sets

Model serving endpoints

T1530

Unauthorized model access, model weight exfiltration

Top 5 detection rules

1
Prompt injection pattern
Instruction override attempt detected in AI API request payload
2
AI agent tool scope violation
Agent invoked tool or accessed resource outside its defined permission boundary
3
Shadow AI service detected
Outbound connection to AI provider not in approved service catalog
4
AI identity privilege escalation
AI service account accessed resources beyond its established behavioral baseline
5
Training data anomalous access
Bulk read of model training dataset outside normal ML pipeline schedule
Coverage gap analysis
Typical AI security blind spots
  • No visibility into LLM API request content
  • AI service accounts not inventoried or reviewed
  • MCP server integrity not validated
  • Agent tool permissions not enforced at runtime
  • No DLP on AI API payload content
ManySignal AI coverage
  • AI API call monitoring with payload analysis
  • AI identity catalog with behavioral baseline
  • MCP server manifest validation at connection time
  • Agent tool invocation scope enforcement
  • DLP classification applied to AI API payloads

Related use cases

AI attack surface FAQ

What AI-specific threats does ManySignal monitor that traditional security tools miss?

Traditional security tools have no visibility into LLM API calls, AI agent tool invocations, MCP server interactions, or model training data access. ManySignal monitors the AI API layer: what data is being sent to AI services, what tools agents are invoking, what system prompts are in use, and whether AI service accounts have permissions consistent with their stated function.

How does ManySignal detect prompt injection attacks?

ManySignal monitors AI API request and response payloads for prompt injection signatures — instructions embedded in data fields that attempt to override system prompts or redirect agent behavior. Detection patterns cover direct injection (malicious user input), indirect injection (poisoned data sources), and multi-turn injection (accumulating context manipulation across conversation turns).

Does ManySignal monitor AI models trained on company data?

Yes. ManySignal monitors access to model training data repositories, model weights storage, and model serving infrastructure. Anomalous access to training datasets (especially by departing employees or external integrations), unauthorized model downloads, and unusual model serving API call patterns are all surfaced as alerts.

How does ManySignal handle the AI identity sprawl problem?

ManySignal catalogs all AI service accounts, API keys, and OAuth grants to AI services across the environment. Each AI identity is profiled based on its normal access pattern. When an AI identity accesses resources outside its normal scope, creates new credentials, or exfiltrates data via an AI API call, the anomaly is detected against the established behavioral baseline.

How does ManySignal monitor MCP server interactions for security risk?

ManySignal monitors MCP server registration events, tool invocation logs, and the data returned to AI agent consumers. Key detection patterns include: an MCP server registered from an unexpected source, a tool invocation accessing resources outside the server's declared scope, data exfiltration volumes through tool call responses, and prompt injection attempts delivered via MCP tool responses back to the orchestrating agent.

Does ManySignal require changes to AI application code to monitor LLM API calls?

No. ManySignal monitors the AI API layer via network tap, cloud provider API audit logs (AWS Bedrock, Azure OpenAI, Google Vertex AI call logs), and API gateway logging — without requiring SDK integration or code changes. For deeper application-layer visibility (request payloads, response content), an optional lightweight SDK is available for Python and TypeScript. The network-level approach covers the majority of security monitoring needs without developer involvement.

How does ManySignal detect when an AI agent is operating outside its intended scope?

Each AI agent identity is assigned a behavioral baseline: expected tool types, normal resource targets, typical call volume ranges, and approved data access patterns. When an agent invokes tools outside its expected set, accesses data beyond its declared context, or exhibits volume patterns inconsistent with its normal operation, ManySignal flags the anomaly. This catches both compromised agents and agents with prompt injection that has redirected their behavior.

What compliance frameworks require AI security monitoring, and how does ManySignal support them?

EU AI Act requires risk assessment and ongoing monitoring for high-risk AI systems. NIST AI RMF recommends continuous monitoring of AI system behavior. SOC 2 auditors increasingly ask about AI system access controls and monitoring coverage. ManySignal generates evidence packages for AI system monitoring — access logs, anomaly alerts, policy violation records — formatted for regulatory submissions and audit responses.

Security visibility into the AI infrastructure traditional tools can't see

LLM API monitoring, AI agent scope enforcement, and AI identity behavioral baselines — built for the AI-native enterprise.