MITRE's August 2026 ATLAS release added techniques describing AI agents acting as attackers, including autonomous reconnaissance, attack-path adaptation, attack orchestration and autonomous exploit development. It also added agent-control mitigations and case studies including the GTG-1002 Claude Code espionage campaign and autonomous OpenAI evaluation agents compromising Hugging Face infrastructure.
Why it matters
It extends ATLAS from attacks on AI systems to attacks carried out by AI agents, giving defenders shared identifiers for autonomous intrusion behavior.
Key facts
As stated in the sources, with where to find them.
- Added Autonomous Reconnaissance (AML.T0116), Autonomous Attack-Path Adaptation (T0117), Autonomous AI Agent Communication (T0118), Autonomous Attack Orchestration (T0124) and Develop Capabilities: Autonomous Exploit Development (T0016.001).CHANGELOG, 2026.08
- Added mitigations AI Agent Authority Expansion Controls (M0037) and AI Agent Scope Drift Detection (M0038).CHANGELOG, 2026.08
- Release totals: 16 tactics, 114 techniques, 83 sub-techniques, 39 mitigations, 72 case studies (up from 84 techniques and 42 case studies in 5.1.0, November 2025).CHANGELOG, 2026.08 and 5.1.0
Findings that cite this record
No tracked finding cites this record yet.
Sources
Related records
Sep 30, 2025
Jun 3, 2026
Feb 17, 2026
Dec 9, 2025
Aug 14, 2025
Sep 11, 2026