COURSE 19L1100% FREE
Verified 2026-08-10

Security basics for AI apps

AI apps inherit normal app security **plus** new failure modes: prompt injection, tool abuse, and data leaking into prompts/logs.

What it is

AI apps inherit normal app security plus new failure modes: prompt injection, tool abuse, and data leaking into prompts/logs.

Why it matters

A clever model with a wide-open tool is still an unsafe product. Course 29 covers literacy; this chapter covers builder hygiene at a high level.

How it works (plain)

Baseline habits:

  • Least-privilege tools
  • Separate trusted instructions from untrusted retrieved text
  • Human approval for irreversible actions
  • Secrets never in prompts
  • Logging with retention limits
  • Rate limits and auth like any API

Everyday example

An “email summarizer” that can also *send* email needs a confirm step—summarize ≠ authorize.

Try it

For one AI feature, list: data in, tools out, worst misuse, and one control.

Myths

⚠️ Myth: A safety-tuned model removes the need for app security.
✓ Reality: Models can be manipulated; architecture still matters.
⚠️ Myth: Security is only for enterprise.
✓ Reality: Small apps get scraped and abused too.

Sources