Categorize LLM application risks by the control layer most responsible for mitigation.
Place each risk where the first serious control usually belongs. Input and retrieval boundary Output validation Tool and plugin permissions User workflow and review Operations and monitoring A PDF tells the assistant to ignore developer instructions Generated SQL is executed without validation or parameterization Assistant can email customers and create refunds with the same broad token Agents copy AI legal wording into customer emails without checking sources A long prompt causes repeated expensive calls and queue exhaustion Retrieved snippets include secrets from an internal admin page Model output contains HTML that is rendered directly in an admin console Plugin accepts…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in