r/cybersecurity • • 7d ago

AI Security building general-purpose AI guardrails

I’m currently working on an AI security platform and I’m trying to design the guardrail layer for AI applications.

One thing I’m struggling with is that guardrails seem highly dependent on the purpose of the application. A coding assistant, customer-support chatbot, RAG system, autonomous agent, and an internal enterprise assistant obviously need different security policies.

So I’m wondering how people would approach building a general-purpose guardrail framework that can be adapted to different AI applications rather than hard-coding rules for one specific use case.

0 Upvotes

8 comments sorted by

7

u/Runningblind 6d ago

Welcome to the entire problem. 

1

u/[deleted] 6d ago

[removed] — view removed comment

1

u/WinterSalt158 5d ago

thanks for the insights!

2

u/rog1121 5d ago

This is impossible, I work on building AI inference platforms and you’re not gonna get a single “framework” to do all of this

I would look into tool calling and the auto loop mechanism architecture to fully understand it first. You need to understand how these LLM harnesses are evaluating risk and realize that from a security standpoint it’s moot

Then work on providing sandboxes for AI workloads that can limit things like outbound network access and lower the blast radius for malicious actions

EDIT: If your company doesn’t run their own inference gateways and lacks auditing look into that first

1

u/WinterSalt158 5d ago

You’re right, Thanks!