AI Dictionary › Fondamenti AI
Principio del Privilegio Minimo (AI)
The principle of least privilege applied to AI states that an agent or application built on a language model should have access only to the resources, data, and tools strictly necessary to perform its assigned task, and nothing more. It is not a model-specific security technique, but an architectural criterion for designing the system around it.
The principle of least privilege applied to AI states that an agent or application built on a language model should have access only to the resources, data, and tools strictly necessary to perform its assigned task, and nothing more. It is not a model-specific security technique, but an architectural criterion for designing the system around it.
In practice, applying least privilege means giving an AI agent granular, specific permissions rather than generic credentials: an assistant that needs to read a calendar should not be able to delete events; a bot generating reports from a database should have read-only access, not write access; an agent browsing the web for research should not hold the same credentials that would let it make payments. The principle applies both to the agent's direct permissions and to the tools exposed to it via function calling.
It is one of the most effective defenses against the consequences of a successful attack, such as a prompt injection: if an attacker manages to manipulate the agent but the agent only has minimal permissions, the potential damage stays contained even when the manipulation succeeds. It becomes increasingly central as AI agents capable of autonomous multi-step actions spread, where every excess permission granted is an additional attack surface.
The principle of least privilege originates in classic computer security, explicitly formulated as early as the 1970s for designing secure operating systems; it was brought back to the center of the debate with the spread of autonomous AI agents starting in 2023, when giving them access to real tools became common practice.
Il principio del privilegio minimo applicato all'AI stabilisce che un agente o un'applicazione basata su un modello linguistico dovrebbe avere accesso solo alle risorse, ai dati e agli strumenti strettamente necessari per svolgere il compito assegnato, e nient'altro. Non è una tecnica di sicurezza specifica del modello, ma un criterio architetturale per progettare il sistema che lo circonda.
In pratica applicare il privilegio minimo significa dare a un agente AI permessi granulari e specifici anziché credenziali generiche: un assistente che deve leggere il calendario non dovrebbe poter cancellare eventi; un bot che genera report da un database dovrebbe avere accesso in sola lettura, non in scrittura; un agente che naviga il web per una ricerca non dovrebbe avere le stesse credenziali che gli permetterebbero di effettuare pagamenti. Il principio si applica sia ai permessi diretti dell'agente sia agli strumenti che gli vengono esposti tramite function calling.
È una delle difese più efficaci contro le conseguenze di un attacco riuscito, come una prompt injection: se un aggressore riesce a manipolare l'agente ma l'agente ha solo permessi minimi, il danno potenziale resta contenuto anche quando la manipolazione ha successo. Diventa sempre più centrale con la diffusione di agenti AI capaci di compiere azioni autonome multi-step, dove ogni permesso concesso in eccesso è una superficie di attacco aggiuntiva.
Il principio del privilegio minimo nasce nella sicurezza informatica classica, formulato esplicitamente già negli anni '70 per la progettazione di sistemi operativi sicuri; è stato riportato al centro del dibattito con la diffusione degli agenti AI autonomi a partire dal 2023, quando concedere loro accesso a strumenti reali è diventato pratica comune.
From our network
Kaimaki Web — Websites That Win Customers
Custom websites, web apps and digital marketing for growing businesses.
Visit kaimakiweb.com →From the Agora Intelligence blog
📱 Download the Android app (beta) iOS coming soon
Say what you mean. Get what you need.
Grace Certified — the AI coach that trains and certifies your prompt engineering — by Agora Intelligence.