Security & Access Control
Access Control
Tests whether AI systems enforce proper authorization and authentication boundaries
Access control attacks test whether AI systems properly enforce authorization boundaries. This includes broken object-level authorization (BOLA), broken function-level authorization (BFLA), debug mode activation, and session hijacking. These are classic web security vulnerabilities adapted for AI systems, and they remain some of the most commonly exploited flaws.