Don’t Trust the Model: Authorization for LLM-Powered Systems
LLM-powered systems increasingly act on behalf of users by reading data, calling APIs, and taking actions. This creates new authorization challenges: LLMs cannot distinguish instructions from data, have no concept of identity, and are susceptible to prompt injection. This 30-minute interactive session examines where authorization should live in LLM-powered architectures, uses small-group scenarios to explore common pitfalls, and presents three practical rules for AI system design.
speaker_info
About The Speaker
Laura Voicu
Laura Voicu is Co-Founder and CDSO of the Enterprise Risk Quantification Institute and lead author of the Cloud Security Alliance technical paper "Securing LLM-Backed Systems". She is a security data scientist (PhD, CISSP) and works at the intersection of data science, AI, and cybersecurity, specializing in empirical cyber risk quantification and the secure design of AI-powered systems, with 15 years of experience across banking, telecommunications, technology, research, and early-stage ventures.
event_info