Security basics for AI apps
AI apps inherit normal app security **plus** new failure modes: prompt injection, tool abuse, and data leaking into prompts/logs.
What it is
AI apps inherit normal app security plus new failure modes: prompt injection, tool abuse, and data leaking into prompts/logs.
Why it matters
A clever model with a wide-open tool is still an unsafe product. Course 29 covers literacy; this chapter covers builder hygiene at a high level.
How it works (plain)
Baseline habits:
- Least-privilege tools
- Separate trusted instructions from untrusted retrieved text
- Human approval for irreversible actions
- Secrets never in prompts
- Logging with retention limits
- Rate limits and auth like any API
Everyday example
An “email summarizer” that can also *send* email needs a confirm step—summarize ≠ authorize.
Try it
For one AI feature, list: data in, tools out, worst misuse, and one control.
Myths
- ⚠️ Myth: A safety-tuned model removes the need for app security.
- ✓ Reality: Models can be manipulated; architecture still matters.
- ⚠️ Myth: Security is only for enterprise.
- ✓ Reality: Small apps get scraped and abused too.
Sources
- OWASP Top 10 for LLM Apps: https://owasp.org/www-project-top-10-for-large-language-model-applications/ ↗
- NIST AI RMF: https://www.nist.gov/itl/ai-risk-management-framework ↗
- Course 29 jailbreaks-and-injection (literacy, no how-to)
