Access controls protect the service, not every answer

Restricting who may call an AI system says nothing about what it will tell the people who are allowed to.

If the model can reach data that a particular authorised user should not see, the access control at the door has not helped. The permissions that matter are the ones on what the system can retrieve on that user's behalf, not on whether the user may ask.

More on AI and LLMs