with amazon its pretty standard to scope permissions as an allow list.
if you want an llm to do any operations on your stuff, give it a role with access to only stuff you want it to be able to touch
if you want an llm to do any operations on your stuff, give it a role with access to only stuff you want it to be able to touch
It actually seems like they knew ahead of time and proceeded anyway, but are just using this critique as a way to shift blame.