Glossary · Security & governance

Defense in Depth

Using independent preventive, detective, and corrective controls at several system boundaries so one failed control does not determine the outcome.

Why it matters

AI systems combine probabilistic models, untrusted content, tools, and external services, making any single filter or prompt an inadequate security boundary.

In practice

Pair instruction controls with narrow permissions, sandboxing, schema validation, approval for consequential actions, monitoring, and a tested recovery path.

Common confusion

More controls are not automatically better. Layers should address distinct failure modes and remain testable rather than repeat the same assumption.

Related terms

Sources

Browse the learning paths to see this term in context — every lesson is free to read.