Retrieved Text Is Part of the Prompt
There is no parser inside a language model that separates the instructions you wrote from the document it just retrieved. Every control that assumes there is one fails in the same direction.
Governing generative AI, securing AI-enabled workflows, and assessing AI vendors.
9 articles
There is no parser inside a language model that separates the instructions you wrote from the document it just retrieved. Every control that assumes there is one fails in the same direction.
A GenAI security review that spends its budget on whether the model can be talked into saying something forbidden has assessed the half of the system that does not act. The half that acts is the tool list.
Building an autonomous crafting explorer surfaced real lessons about observability, cost governance, and security posture that apply far beyond a game.
An agent's permissions are whatever its tools can reach, not whatever its role description says, so the policy has to be written at the tool boundary and tested like a control.
AI-enabled workflows are now embedded in daily operations. Security teams need practical guardrails that protect data without blocking productivity.
AI vendor risk does not end at demo day. Security teams need stronger procurement and contract controls before enterprise rollout.
As AI capabilities accelerate, security architecture has to evolve from static reviews to faster, risk-informed design guardrails.
Generative AI adoption is outpacing governance. Security leaders need a practical framework before shadow AI becomes the next shadow IT.
Generative AI is everywhere in security conversations, but value only comes when teams tie AI use cases to measurable outcomes and operational reality.