AI agents need a different security model than chatbots

vasiliyivanov · reddit · 2026-08-28

The author argues that once an AI system can use tools, read files, send messages, browse, access SaaS accounts or trigger automations, the security question shifts from "can this model answer safely?" to "what can this model do, with whose credentials, against which data, under which approval rules?"

The controls that matter most: scoped permissions, human confirmation for irreversible actions, audit logs, separation of read and write access, prompt injection awareness, no silent access to broad workspaces, and a clear rollback path for automations.

Original post →

More from coding & agent

coding & agent channel →