Published
Why permissions belong in front of the model, not in the prompt
Is it enough to tell an AI assistant in its prompt not to reveal confidential content?
No. An instruction in the prompt is a request to the language model, not a rule: what the model has read, it can repeat. Only a fixed, verifiable rule outside the model is reliable, one that decides before the search which documents a request can reach at all.