Secure AI Begins With Bounded Access
Apply familiar security disciplines to the new pathways created by models, tools and retrieved content.

Connecting a model to a business system creates a new route through which information and actions can travel. That route needs an identity, a purpose and a boundary.
A confident instruction in a prompt cannot substitute for an access control enforced by the application. The model may misunderstand a task or encounter hostile instructions in material it reads. Design the surrounding system to limit what an error can affect.
Start with the smallest useful permission
Give each workflow only the data and actions needed for its job. Keep reading, drafting and committing changes as separate capabilities where the risk warrants it. Enforce authorisation at the tool or service boundary using the user’s legitimate access context.
Avoid a shared administrator credential that gives every agent the same reach. Review service identities, secrets handling and revocation paths. In an illustrative document assistant, access should follow the user’s entitlement to a document, including during retrieval and citation.
OWASP’s excessive-agency guidance highlights unnecessary functionality, permissions and autonomy as sources of risk. Read the OWASP guidance.
Treat connected content as untrusted input
An external page, email or repository file can contain instructions. Those instructions are data to assess, not authority to change the workflow’s purpose or permissions.
Use layered controls: narrowly defined tools, validated parameters, restricted destinations, approval for consequential actions and useful monitoring. Test whether the system remains within its boundary when retrieved material is misleading or adversarial. No single prompt or content filter should carry the entire security argument.
Retain ordinary engineering disciplines as well: patch dependencies, review changes, protect credentials and prepare recovery procedures. The NCSC’s secure AI development guidance covers security throughout design, development, deployment and operation. Read the NCSC guidance.
Test what the system must refuse
A useful security review includes attempts to reach another user’s records, send data to an unapproved destination or perform an action outside the task. Record the result at the system boundary, not just the model’s verbal refusal.
Start with one agent and list every tool it can call. For each capability, identify its business need, enforced scope, owner and revocation method. Remove access that has no defensible purpose.







