Agent permissions

What an AI agent can do to you is decided by the tools it holds, not by how carefully it was instructed.

Instructions are requests. Permissions are facts. An agent told to be careful with the customer database, but holding a key that can delete it, is one convincing piece of text away from deleting it. Scoping the tools is the control that still works when the model has been talked into something, which is why it matters more than the wording at the top of the prompt.

Checked against the primary source.

More on AI security