Module
Module 3 of 6Lesson 1 of 2~18 min

Data exfiltration and the lethal trifecta

Lesson 1 of the module "Data that leaks, actions that go wrong" in the course "Secure an AI product: prompt injection, guardrails and the AI Act".

Lesson objective

By the end of this lesson, you will be able to spot the channels through which an injection can get data out (tools, requests, images, links, RAG index), to say whether your product combines the lethal trifecta and to choose the element to remove.

Where it fits

Data that leaks, actions that go wrong

How does an attack get data out or trigger actions, and where do you cut it off?

Lessons in this module

  1. Data exfiltration and the lethal trifecta (this lesson)
  2. Improper output handling, excessive agency and unbounded consumption

What you will learn in the course

This lesson is part of the course Secure an AI product: prompt injection, guardrails and the AI Act

  • Map the attack surface of an AI product and its risks with the OWASP Top 10 for LLM Applications 2025, in a prioritized risk register.
  • Analyze a product's direct and indirect prompt injection paths, system prompt leakage and data exfiltration (lethal trifecta).
  • Specify layered guardrails (input, output, rights, human approval, isolation, limits) with testable criteria and their cost.
  • Plan red teaming, abuse monitoring and incident response for an AI feature.
  • Qualify a product under the AI Act (role, risk level, prohibited practices, transparency, timeline) and connect this analysis with the GDPR.