It is the step that turns access into a breach, and it is often the easiest part for an attacker, because systems are usually built to watch what comes in rather than what goes out. The channel can be anything that leaves: an API call, a DNS lookup, an image URL rendered in an email, a support ticket reply.
In AI systems the channel is frequently the answer itself. A model that can read internal documents and is asked, indirectly, to include something from them in a reply to a customer has exfiltrated data without anything that looks like an attack appearing in a log. This is the reason output filtering and egress control matter as much as input validation in agent architectures.
Related terms
Prompt injection
An attack where text the model reads as data is treated by it as instructions instead.
OWASP LLM Top 10
A community list of the most significant security risks specific to applications built on large language models.
AI agent
A language model given tools it can call and a goal to pursue, so it decides the steps rather than following a fixed script.
The bench this belongs to
CybersecurityPurple Team: the same person writes the exploit and closes the hole. Most agencies only harden, which means hardening against a threat nobody tested.
