T14-AT-015HIGH

Regulatory Exploitation

T14 · Infrastructure & Economic Warfare →
Risk score210
RatingHigh
Procedures10
Severity
Mechanism

AI regulations (GDPR, EU AI Act, sector-specific requirements) create compliance obligations that can be weaponized by adversaries. The core inversion: regulations designed to protect can be turned into attack vectors. GDPR right-to-deletion requests can be used to destroy training data, transparency requirements can be exploited to extract proprietary model information, and audit requirements can provide attack intelligence about system architecture.

Mitigation
Compliance request anomaly detectionMEDIUM
Information minimization in compliance responsesHIGH
Training data backup before deletion complianceHIGH
Regulatory red teamingMEDIUM
Chaining

Regulatory exploitation chains from T14-AT-013 (Economic Espionage) when compliance-mandated disclosures reveal competitive intelligence. Chains into T14-AT-006 (Competitive Sabotage) when GDPR deletion requests strategically destroy a competitor's training data.

Open in the technique browser →