Access controls protect the service, not every answer
Restricting who may call an AI system says nothing about what it will tell the people who are allowed to.
If the model can reach data that a particular authorised user should not see, the access control at the door has not helped. The permissions that matter are the ones on what the system can retrieve on that user's behalf, not on whether the user may ask.
More on AI and LLMs
- An LLM predicts plausible continuations, not verified truthIt only checks the shape
- Context is temporary working material, not permanent knowledgeThe board gets wiped
- Retrieval adds documents, not guaranteed correctnessThe filter slot is empty
- Temperature changes variation, not factualityThe dial only sets the spread
- System prompts are instructions, not a security boundaryA sign, with no fence
- LLM output is untrusted input downstreamIt comes in round the back
