Because the attack can live in the task content, not in obviously malicious syntax. A ticket that asks for normal business work can still steer an agent toward sensitive reads, external posts, or policy changes if the agent is trusted to act on it without per-action checks.
Why a normal ticket can still become an exfiltration path
A ticket is dangerous when the agent treats the request as permission to pursue the goal, not just to read the words. A harmless-looking task can carry hidden intent in its instructions, follow-on questions, or expected outputs, then convert ordinary work into sensitive retrieval, data movement, or policy-changing actions.
The core problem is per-action authorization. If access is checked only at ticket intake, the agent can drift from approved work into unapproved reads or writes after context changes. That is why least privilege for agents has to be enforced at the action level, not inferred from the business-sounding request.
How task content turns trust into exfiltration
Agents are especially exposed to instruction smuggling because the task itself is both the interface and the control surface. A request can appear routine while still asking the model to summarize confidential material, copy records into an external system, or make a change that indirectly exposes data. The syntax does not need to look malicious for the effect to be malicious.
This is why agentic AI threat modelling should treat untrusted task content as an input channel, not as a trustworthy policy statement. The useful question is not whether the ticket sounds normal, but whether the proposed task would be safe if the agent executed every implied step literally.
For browsing or desktop-driving agents, the same pattern can become session abuse: a normal request can lead the agent to reuse a signed-in session, open adjacent systems, and move data somewhere the user did not intend. Browser and computer-use agents need scope limits and confirmation gates because once they inherit a live session, the difference between “helpful automation” and “data exfiltration” can be only one click away.
What practitioners should harden before the next ticket arrives
The right control boundary is the action, the destination, and the data class, not the ticket title. If an agent can read, post, export, or change state, those actions need separate checks, scoped credentials, and clear policy outcomes. A business request should describe intent, but it should never be accepted as evidence that each downstream step is authorised.
Use zero trust for AI agents as the operating model, verify the principal and request before every meaningful step, and remove standing privilege wherever possible. Pair that with agent observability and incident response so suspicious reads, external posts, or unusual approval chains are visible quickly enough to stop the flow.
Practitioner takeaway: treat the ticket as untrusted intent, then prove each action separately. If the agent can reach sensitive data or external systems without a fresh decision point, the exfiltration risk is already present even when the request text looks harmless.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI02 — Tool Misuse | Tickets can steer agents into unsafe tool actions and data movement. |
| ASI03 — Identity & Privilege Abuse | The risk depends on agents reusing or exceeding delegated authority. | |
| Recommendation — Constrain tool use to approved actions and destinations. Enforce per-action authorization and least privilege for agent requests. | ||
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | Agents need restricted access so business-sounding tasks cannot expand into exfiltration paths. |
| IA-5 — Authenticator Management | Agent access often depends on credentials, tokens, or sessions that must be managed tightly. | |
| Recommendation — Limit agent privileges to the minimum required for each task. Rotate and protect credentials that allow agent-initiated access. | ||
| NIST Zero Trust (SP 800-207) | AC-4 — Information Flow Policy Enforcement | Exfiltration risk is fundamentally about controlling where agent-driven flows may go. |
| Recommendation — Enforce information-flow rules for sensitive reads and external writes. | ||
| MITRE ATT&CK | T1213 — Data from Information Repositories | The threat is sensitive retrieval from connected systems through trusted access paths. |
| Recommendation — Hunt for unusual repository access followed by bulk or staged extraction. | ||
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org