LANDMARK · 8 MIN · JUDGE
Security boundaries
After this landmark, you can describe an AI feature in terms of what it can read, what it can change, and who can trigger it — and see why that boundary, not the model’s politeness, is the real security control.
You can still explore it. We’re showing the shared explanation and a related practical view without hiding the knowledge.
Most conversation about AI safety is about outputs: will it say something harmful, can it be talked into breaking its rules. That’s worth caring about, but it isn’t where the damage usually comes from. The damage comes from reach. A model that can only produce text can, at worst, produce bad text. A model wired into your mailbox, your files, your ticketing system, or your production database can send, delete, overwrite, and expose. Jailbreaking — coaxing a model past its own refusals — matters exactly as much as the permissions sitting behind it. So the useful question about any AI feature is not “can it be tricked?” (assume yes) but “when it is tricked, what can it actually touch?” Draw that boundary explicitly: what it can read, what it can change, and who or what can set it off.
This is the canonical concept. It stays the same across learner lenses so personalization never changes the underlying facts.
What this looks like for you
When an app asks to connect your email, calendar, or cloud drive to an AI feature, read what access it wants. “Read your messages” and “send messages on your behalf” are very different permissions, and the second one is the one that can act without you. Grant the narrow one where you can, and disconnect what you’ve stopped using.
MAKE A DECISION
A team wants to give an internal assistant access to the company file store so staff can ask questions about policies. Which setup best limits the damage if the assistant is manipulated by a booby-trapped document?
CARRY THISPick one AI feature you or your team has connected to something real. Write three lines: what it can read, what it can change, and what can trigger it. Note any line you cannot answer confidently.