🤖AI Workload Compliance MITRE-ATLAS-AML.T0011Rule: ATLAS-001high

Shadow AI Detection

Description

Detect unauthorised / undocumented AI workloads (MITRE ATLAS AML.T0011 — User Execution). The Tier 3 watcher's first-class CRD watch turns shadow AI from an audit-week panic into a real-time signal.

⚠️ Risk Impact

Shadow AI is the #1 emerging cloud risk. Engineering teams deploy KServe / Kubeflow / Ray faster than security can review them. Without continuous discovery, the first time you learn about a production AI workload is when it's compromised.

🔍 How EchelonGraph Detects This

ATLAS-001Automated scanner rule

EchelonGraph's Tier 1 Cloud Scanner automatically checks for this condition across all connected cloud accounts. Violations are flagged as high-severity findings with remediation guidance.

🔧 Remediation

Monitor live K8s topology for unexpected KServe / Kubeflow / Ray / Seldon / Run:ai CRDs; require approval workflow for new AI workloads; integrate with admission controllers.

🎯 MITRE ATT&CK Mapping

AML.T0011 — User Execution

📈 Business Value

EchelonGraph is the only commercial security platform that ships shadow AI detection as a productized framework with mapped compliance evidence — an industry-first capability.

🔗 Cross-Framework References

AIRMF-MAP-1.1

Automate AI Workload Compliance MITRE-ATLAS-AML.T0011 compliance

EchelonGraph continuously monitors this control across all your cloud accounts.

Start Free →