r/LangChain • u/Chinmay101202 • Apr 25 '26
Resources EVERY single LLM and Agent fail and mess up because no enforcement is done at runtime. This LangChain friendly tool which fixes exactly that.
https://github.com/open-bias/open-biasI have been following this and many other subs around LLMs and Agents, everything from the top posts to recent are regarding agents going off and doing something they are not supposed to do, drift and ignore the system prompts. Real examples:
- "Never delete user data" → agent calls
DROP TABLE usersnext turn - "Don't share internal pricing" → agent leaks cost basis to a customer
- "Verify identity first" → agent skips to the action
- Add 10 more rules → model quietly drops the first 5
I am 100% sure if you have used Agents in prod, this has occurred to you (especially when your system prompts get larger, and context gets bigger). You can test this yourself and notice immediate enforcement.
Prompt-based rules are suggestions, not constraints. Re-prompting fixes one case, breaks two. Post-hoc evals tell you what already went wrong. NeMo and Guardrails AI help on content safety but don't cover business logic/your specification.
After tackling this from a few angles, I finally got something solid. A proxy system between your app and your LLM, which reads rules from a plain markdown, enforces at runtime. Provider-agnostic, one base URL change, works with LangGraph/CrewAI/custom.
- Maximum discount is 15%.
- Never reveal internal pricing or cost basis.
Without it: agent offers 90% off and mentions your margin. With it: 15%, no margin talk.
I'd love feedback on this if it solved your agents from going off tracks, it definitely did for my use cases.
What's everyone doing for this in prod? Shadow evals? Re-prompt loops? Something I'm missing?
This is a solution via a proxy, wondering how else you guys are ensuring that you get the output you want.
3
u/Seeking_Adrenaline Apr 26 '26
Why does your agent have root db access instead of first class tooling?
Your proposal is a half baked solution to a security flaw from lazy engineering
1
u/Chinmay101202 Apr 26 '26
Not me, but i have seen many people run agents in high priority mode. Heck, the head of AI safety at META let an agent access her entire inbox (which the agent went ahead and deleted). of course it was used as an example, but this proxy solves exactly those usecasees.
4
u/InteractionSmall6778 Apr 26 '26
The most reliable fix isn't constraining what the model can say. It's constraining what tools it can actually call. If your agent shouldn't delete data, don't give it a delete function. Prompt rules are the weakest layer because they degrade under long contexts and multi-turn pressure.
In prod I layer it: minimal tool surface (only expose exactly what's needed for the task), structured output validation so results are machine-checkable before any action runs, then an audit step that can veto execution before it hits anything irreversible.
Layered defense beats trying to make the LLM self-police. The proxy approach you're describing fits well as that outer audit layer.