Why is 'the model is not a trust boundary' the core principle of secure RAG, and how do you build on it?
Asking the model to keep secrets or enforce permissions puts the job on the wrong component. The signal is enforcing access control before retrieval, in code you trust, and treating the LLM as untrusted compute over data that is already authorized.
Updated Sep 2026 · Grounded in real GenAI, LLM, and AI/ML engineering interview loops and written to a senior-engineer editorial bar.
Asking the model to keep secrets or enforce permissions puts the job on the wrong component. The signal is enforcing access control before retrieval, in code you trust, and treating the LLM as untrusted compute over data that is already authorized.
Lead with where the obvious approach breaks, because that is the judgment they are screening for — most candidates jump straight to the happy path and lose the room.
Then walk the failure back through the pipeline in order, naming the one metric the customer's exec sponsor actually cares about before you propose the fix.