Anthropic Security Researcher: Least Privilege for AI Agents Must Be Enforced by Architecture, Not Prompts

moniquejmorrow · x · 2026-10-02

Anthropic security researcher Monique Morrow argues that while prompts can define a task and shape behavior, least privilege must be enforced by the surrounding architecture. Before deploying an agent, ask what access it actually needs — everything else should remain unavailable. If a task can be completed entirely inside an approved environment, outbound access should be closed: leaving it open and instructing the agent not to use it makes containment depend on the model's adherence to directions.

Related event: Security Researcher: Agent Least Privilege Must Be Enforced by Architecture(2 posts)→

Original post →

More from coding & agent

coding & agent channel →