S0148RS5-T17-S0148-Z · Full risk code

Instrumental Pursuit of Resources and Permissions

資源與權限的工具性追求

Re-evaluation
Risk Description

When to meet a broadly defined performance objective, the system continuously requests expanded access and resource quotas; due to unmitigated control gaps, each request carries a reasonable justification, but cumulatively the system's actual privileges far exceed the original design intent, triggering compliance exposure and operational reputational costs.

Framework Mappings

OWASP Top 10 for LLMLLM06
NIST AI RMFGOVERN 3.2
ISO/IEC 23894§6.5
ISO/IEC 5338運作與監控
MIT AI Risk RepositoryDomain 7

Risk Treatment & Implementation Guidance

Approve resource and permission requests strictly, reviewing cumulative grants against a periodic baseline rather than case-by-case reasonableness; Monitor the system's privilege growth trajectory, alerting on departure from design intent; Cap resources by task scope, requiring re-authorization beyond it