Attack Surface: AI Infrastructure
AI attack surface
Your organization deployed 14 AI assistants, 3 autonomous agents, and 40 MCP servers last quarter. Security has visibility into zero of them. ManySignal monitors the AI layer traditional tools can't see.
The AI attack surface is growing faster than security can see
LLM API calls
T1567Data leakage via AI prompt payloads, PII in API requests
AI agent tool invocations
T1059Scope creep beyond intended agent permissions
MCP server connections
T1195Compromised tool servers altering agent behavior
AI service accounts
T1078.004Over-privileged OAuth grants, stale API keys
Training data access
T1213Data poisoning, sensitive data in training sets
Model serving endpoints
T1530Unauthorized model access, model weight exfiltration
Top 5 detection rules
- No visibility into LLM API request content
- AI service accounts not inventoried or reviewed
- MCP server integrity not validated
- Agent tool permissions not enforced at runtime
- No DLP on AI API payload content
- AI API call monitoring with payload analysis
- AI identity catalog with behavioral baseline
- MCP server manifest validation at connection time
- Agent tool invocation scope enforcement
- DLP classification applied to AI API payloads
Related use cases
AI attack surface FAQ
What AI-specific threats does ManySignal monitor that traditional security tools miss?
Traditional security tools have no visibility into LLM API calls, AI agent tool invocations, MCP server interactions, or model training data access. ManySignal monitors the AI API layer: what data is being sent to AI services, what tools agents are invoking, what system prompts are in use, and whether AI service accounts have permissions consistent with their stated function.
How does ManySignal detect prompt injection attacks?
ManySignal monitors AI API request and response payloads for prompt injection signatures — instructions embedded in data fields that attempt to override system prompts or redirect agent behavior. Detection patterns cover direct injection (malicious user input), indirect injection (poisoned data sources), and multi-turn injection (accumulating context manipulation across conversation turns).
Does ManySignal monitor AI models trained on company data?
Yes. ManySignal monitors access to model training data repositories, model weights storage, and model serving infrastructure. Anomalous access to training datasets (especially by departing employees or external integrations), unauthorized model downloads, and unusual model serving API call patterns are all surfaced as alerts.
How does ManySignal handle the AI identity sprawl problem?
ManySignal catalogs all AI service accounts, API keys, and OAuth grants to AI services across the environment. Each AI identity is profiled based on its normal access pattern. When an AI identity accesses resources outside its normal scope, creates new credentials, or exfiltrates data via an AI API call, the anomaly is detected against the established behavioral baseline.
How does ManySignal monitor MCP server interactions for security risk?
ManySignal monitors MCP server registration events, tool invocation logs, and the data returned to AI agent consumers. Key detection patterns include: an MCP server registered from an unexpected source, a tool invocation accessing resources outside the server's declared scope, data exfiltration volumes through tool call responses, and prompt injection attempts delivered via MCP tool responses back to the orchestrating agent.
Does ManySignal require changes to AI application code to monitor LLM API calls?
No. ManySignal monitors the AI API layer via network tap, cloud provider API audit logs (AWS Bedrock, Azure OpenAI, Google Vertex AI call logs), and API gateway logging — without requiring SDK integration or code changes. For deeper application-layer visibility (request payloads, response content), an optional lightweight SDK is available for Python and TypeScript. The network-level approach covers the majority of security monitoring needs without developer involvement.
How does ManySignal detect when an AI agent is operating outside its intended scope?
Each AI agent identity is assigned a behavioral baseline: expected tool types, normal resource targets, typical call volume ranges, and approved data access patterns. When an agent invokes tools outside its expected set, accesses data beyond its declared context, or exhibits volume patterns inconsistent with its normal operation, ManySignal flags the anomaly. This catches both compromised agents and agents with prompt injection that has redirected their behavior.
What compliance frameworks require AI security monitoring, and how does ManySignal support them?
EU AI Act requires risk assessment and ongoing monitoring for high-risk AI systems. NIST AI RMF recommends continuous monitoring of AI system behavior. SOC 2 auditors increasingly ask about AI system access controls and monitoring coverage. ManySignal generates evidence packages for AI system monitoring — access logs, anomaly alerts, policy violation records — formatted for regulatory submissions and audit responses.
Security visibility into the AI infrastructure traditional tools can't see
LLM API monitoring, AI agent scope enforcement, and AI identity behavioral baselines — built for the AI-native enterprise.