Abstract: There is provided a method of using a large language model (LLM) for controlling access to a computing cloud, comprising: accessing a log of activity of sessions of the computing cloud, tokenizing the sessions, feeding the tokenized sessions into the LLM, obtaining a loss function per token of the tokenized sessions, computing a session loss for each respective session as an aggregation of the loss function for tokens associated with the respective session, identifying a session including an anomaly associated with a security risk when the session loss of the session is greater than a first threshold, for the identified session, identifying a token(s) having the loss function greater than a second threshold, wherein the identified token(s) denotes the anomaly associated with the security risk, identifying an access event associated with the identified token(s), the access event associated with the security risk, and instructing access control for the access event.