Output Is Untrusted Input
Explain why AI output must be validated before it is executed, stored, or sent.
The AI wrote it is not a validation rule. The sink matters OWASP highlights improper output handling because model output becomes dangerous when it flows into a sensitive sink: code execution, database updates, customer messaging, financial actions, or internal records. The risk is not only a bad answer. It is a bad answer that a system trusts. Why generated text feels safer than it is People trust output from tools they initiated. That trust shortcut is the problem. AI output may contain unsafe commands, fabricated claims, hidden instructions, or malformed data. The model is a generator, not an authorization layer.…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in