ATLASAML.T0112.000
ATLAS index
AML.T0112.000

Local AI Agent

Adversaries may achieve full system compromise by abusing AI agents running locally on a host, such as computer use agents or AI driven browsers. These agents are designed to autonomously interact with the operating system, applications, and external services, often with broad permissions to execute commands, access fi

Framework
MITRE ATLAS
Maturity
Demonstrated
Platforms
Agentic AI
Release
2026.05

Overview

Adversaries may achieve full system compromise by abusing AI agents running locally on a host, such as computer-use agents or AI-driven browsers. These agents are designed to autonomously interact with the operating system, applications, and external services, often with broad permissions to execute commands, access files, manage credentials, and control user workflows.

If an adversary is able to take control of an AI agent's behavior, they effectively gain the same level of access as the agent. This can result in complete control over the machine, including executing arbitrary code, accessing or exfiltrating sensitive data, modifying system configurations, and establishing persistence.

Sources

  1. MITRE ATLAS AML.T0112.000: Local AI Agent — MITRE