Elektrine lite

← Feed

@TindrasGrove@infosec.exchange

Post #1728355

2026-04-27 21:36 UTC

Apropos of nothing whatsoever, it occurs to me that telling an AI agent its limits is, at best, a policy control. It is absolutely not a technical control. And treating policy controls like technical controls demonstrates a fundamental understanding of risk.

Replies (2)

  • @elebertus@eigenmagic.net 2026-04-27 21:42

    @TindrasGrove@infosec.exchange sooooo you’re saying we also now need to write rego for the clankers?

    Open ##2397938

  • @webhat@infosec.exchange 2026-04-27 22:36

    @TindrasGrove@infosec.exchange IMHO I think it's a mistake to tell an LLM explicitly what NOT to do, because that statement will remain in its prompt. What we should be telling it is what to do Don't delete production should be ensure backups are created for rollbacks

    Open ##2397941