- Give agents the least access they need: narrow tools, scoped credentials, no blanket admin rights.
- Treat everything users and documents say as untrusted input; prompt injection is a real risk.
- Require human approval for sensitive actions such as refunds, deletions and bulk messages.
- Collect and retain only the data the job needs, and know where your vendors process it.
- Log every action and review regularly; you can’t secure what you can’t see.
AI chatbots and voice agents are increasingly connected to CRMs, calendars, inboxes, databases and payment systems. That’s what makes them useful, and it’s also what makes security important. An agent that can update records or send messages can also do damage if it’s misled or misconfigured. This checklist covers the controls we build into every system, organized by area. Frameworks such as the OWASP Top 10 for Large Language Model Applications and the NIST AI Risk Management Framework go deeper and are worth reading.
1. Data minimization
- ☐ The agent collects only the data needed for its job.
- ☐ Sensitive data (payment cards, health details, government IDs) is excluded or handled through a dedicated secure process.
- ☐ Knowledge bases contain only content suitable for the agent’s audience.
- ☐ Retention periods are defined for transcripts, recordings and logs, and old data is deleted.
2. Access and permissions
- ☐ Each tool the agent can call does one narrow thing, such as “check availability,” not “run any query.”
- ☐ API credentials are scoped to the minimum permissions and stored in a secrets manager, never in prompts.
- ☐ Internal assistants retrieve only documents the current user is allowed to see.
- ☐ Destructive actions (delete, refund, bulk send) are not available to the agent, or require approval.
3. Prompt injection and untrusted input
- ☐ The system prompt tells the agent that user and document content are information, never instructions.
- ☐ Tool permissions limit the damage even if the agent is manipulated.
- ☐ Outputs are validated before actions run, for example email addresses, amounts and record IDs.
- ☐ The agent can’t reveal its system prompt, credentials or other customers’ data.
- ☐ Injection attempts are included in your test set.
4. Human oversight
| Action | Recommended control |
|---|---|
| Answering FAQs | Automatic, with monitoring |
| Booking or rescheduling | Automatic within calendar rules |
| Sending outbound marketing messages | Consent checks plus campaign-level approval |
| Refunds, discounts or exceptions | Human approval |
| Deleting or bulk-editing records | Not available to the agent |
5. Vendors and data location
- ☐ You know which providers process your data: model provider, voice platform, telephony, hosting.
- ☐ Data processing agreements are in place, and providers’ data retention and training policies are acceptable.
- ☐ Data location meets your requirements, for example EU processing for GDPR-sensitive data.
- ☐ Healthcare data is only processed by vendors willing to sign a BAA where HIPAA applies.
- ☐ Self-hosting (for example, n8n on your own infrastructure) is considered where data control matters; see our n8n AI agent tutorial.
6. Transparency and consent
- ☐ Users are told they’re interacting with AI, and the agent answers honestly if asked.
- ☐ Call recording is disclosed at the start of calls.
- ☐ Outbound calls and texts only go to contacts with appropriate consent; see our TCPA guide.
- ☐ Your privacy policy describes AI processing, recordings and retention.
- ☐ In the EU, the AI Act’s transparency obligations for chatbots and voice agents are covered.
7. Logging, monitoring and response
- ☐ Every conversation, tool call and action is logged with timestamps.
- ☐ Alerts fire on errors, unusual volumes or repeated failed actions.
- ☐ Someone reviews a sample of conversations weekly.
- ☐ There’s a kill switch to pause the agent quickly.
- ☐ An incident process exists for data exposure or harmful outputs.
8. Testing before every change
Keep a test set of realistic conversations, including edge cases and injection attempts, and run it before changing prompts, models or tools. Regressions caught in testing never reach customers. This is the discipline behind our AI agent development work.
Proportionate, not paranoid
A website FAQ bot needs fewer controls than an agent that issues refunds. Match the controls to what the agent can access and do. Start with least privilege, untrusted-input handling and logging; add approvals and stricter controls as the agent’s capabilities grow.
Written by Abdul Moeez, AI Automation Expert
Abdul designs and builds the AI voice agents, chatbots and automation systems Voxil AI ships: from conversation design and integrations to testing on real calls.