AI Dictionary › Fondamenti AI

Least Privilege (AI)

Principio del Privilegio Minimo (AI)

The principle of least privilege applied to AI states that an agent or application built on a language model should have access only to the resources, data, and tools strictly necessary to perform its assigned task, and nothing more. It is not a model-specific security technique, but an architectural criterion for designing the system around it.

Definition

What it is

The principle of least privilege applied to AI states that an agent or application built on a language model should have access only to the resources, data, and tools strictly necessary to perform its assigned task, and nothing more. It is not a model-specific security technique, but an architectural criterion for designing the system around it.

How it works

In practice, applying least privilege means giving an AI agent granular, specific permissions rather than generic credentials: an assistant that needs to read a calendar should not be able to delete events; a bot generating reports from a database should have read-only access, not write access; an agent browsing the web for research should not hold the same credentials that would let it make payments. The principle applies both to the agent's direct permissions and to the tools exposed to it via function calling.

Applications

It is one of the most effective defenses against the consequences of a successful attack, such as a prompt injection: if an attacker manages to manipulate the agent but the agent only has minimal permissions, the potential damage stays contained even when the manipulation succeeds. It becomes increasingly central as AI agents capable of autonomous multi-step actions spread, where every excess permission granted is an additional attack surface.

History & etymology

The principle of least privilege originates in classic computer security, explicitly formulated as early as the 1970s for designing secure operating systems; it was brought back to the center of the debate with the spread of autonomous AI agents starting in 2023, when giving them access to real tools became common practice.

Definizione (italiano)

Il principio del privilegio minimo applicato all'AI stabilisce che un agente o un'applicazione basata su un modello linguistico dovrebbe avere accesso solo alle risorse, ai dati e agli strumenti strettamente necessari per svolgere il compito assegnato, e nient'altro. Non è una tecnica di sicurezza specifica del modello, ma un criterio architetturale per progettare il sistema che lo circonda.

In pratica applicare il privilegio minimo significa dare a un agente AI permessi granulari e specifici anziché credenziali generiche: un assistente che deve leggere il calendario non dovrebbe poter cancellare eventi; un bot che genera report da un database dovrebbe avere accesso in sola lettura, non in scrittura; un agente che naviga il web per una ricerca non dovrebbe avere le stesse credenziali che gli permetterebbero di effettuare pagamenti. Il principio si applica sia ai permessi diretti dell'agente sia agli strumenti che gli vengono esposti tramite function calling.

È una delle difese più efficaci contro le conseguenze di un attacco riuscito, come una prompt injection: se un aggressore riesce a manipolare l'agente ma l'agente ha solo permessi minimi, il danno potenziale resta contenuto anche quando la manipolazione ha successo. Diventa sempre più centrale con la diffusione di agenti AI capaci di compiere azioni autonome multi-step, dove ogni permesso concesso in eccesso è una superficie di attacco aggiuntiva.

Il principio del privilegio minimo nasce nella sicurezza informatica classica, formulato esplicitamente già negli anni '70 per la progettazione di sistemi operativi sicuri; è stato riportato al centro del dibattito con la diffusione degli agenti AI autonomi a partire dal 2023, quando concedere loro accesso a strumenti reali è diventato pratica comune.

Related terms

More in Fondamenti AI

Put it into practice

From our network

Kaimaki Web — Websites That Win Customers

Custom websites, web apps and digital marketing for growing businesses.

Visit kaimakiweb.com →

From the Agora Intelligence blog

More on agora-intelligence.com →

📱 Download the Android app (beta) iOS coming soon

Say what you mean. Get what you need.

Grace Certified — the AI coach that trains and certifies your prompt engineering — by Agora Intelligence.