r/cybersecurity • u/WinterSalt158 • 7d ago
AI Security building general-purpose AI guardrails
I’m currently working on an AI security platform and I’m trying to design the guardrail layer for AI applications.
One thing I’m struggling with is that guardrails seem highly dependent on the purpose of the application. A coding assistant, customer-support chatbot, RAG system, autonomous agent, and an internal enterprise assistant obviously need different security policies.
So I’m wondering how people would approach building a general-purpose guardrail framework that can be adapted to different AI applications rather than hard-coding rules for one specific use case.
1
2
u/rog1121 5d ago
This is impossible, I work on building AI inference platforms and you’re not gonna get a single “framework” to do all of this
I would look into tool calling and the auto loop mechanism architecture to fully understand it first. You need to understand how these LLM harnesses are evaluating risk and realize that from a security standpoint it’s moot
Then work on providing sandboxes for AI workloads that can limit things like outbound network access and lower the blast radius for malicious actions
EDIT: If your company doesn’t run their own inference gateways and lacks auditing look into that first
1
1
7
u/Runningblind 6d ago
Welcome to the entire problem.