Skip to content
Media 365
Book a call
AI

Guardrails & AI Policy

Enforceable limits on what an AI system may say, do and access.

3
reasons we rely on it
1
service
How we use it

We translate your risk policy into implemented controls: input and output filtering, scope restrictions, escalation paths, refusal behaviour, and permissions on every tool an agent can call.

Where it fits

Essential wherever an AI system touches customers, money or regulated data. Industry reporting in 2026 puts the governance gap at around 60% of organisations running agentic AI without adequate controls — that is the gap we close.

Why we rely on it
Policy becomes code, so compliance is demonstrable rather than asserted
Human-in-the-loop thresholds set per decision type, not per system
Aligns with ISO/IEC 42001 practices and Australia's Voluntary AI Safety Standard

A prompt is guidance; a guardrail is a control

Instructing a model to stay on topic is a request. A guardrail is enforcement: filtering on input and output, hard limits on scope, permissions on every tool the system can reach, defined escalation paths, and refusal behaviour agreed in advance with the people who carry the risk.

The gap between those two things is where most AI incidents live. Industry reporting through 2026 puts roughly 60% of organisations running agentic AI without adequate controls — a governance gap that grows more consequential as agents gain the ability to act rather than merely answer.

How the policy gets written

We run a scoping session with your risk, legal and operational stakeholders and answer specific questions: what may this system discuss, what must it never claim, which decisions may it make alone, what happens when it is unsure, who is notified, and how quickly can it be stopped. The answers are written in plain language you can show an auditor.

Then we implement them. Scope restrictions and filters in code, tool permissions enforced at the connection layer, escalation routed to a real queue with a real owner, and logging on everything. Compliance becomes demonstrable rather than asserted, which is the standard external reviewers actually apply.

Human-in-the-loop, calibrated per decision

Oversight is not binary. Drafting an internal email warrants less scrutiny than issuing a refund, determining eligibility, or altering a ratepayer's account. We set thresholds per decision type, document them, and make the review path fast enough that staff genuinely use it — an oversight process people route around is worse than none, because it creates false assurance.

Delivery aligns with ISO/IEC 42001-style AI management practice and Australia's Voluntary AI Safety Standard, and every deployment ships with a tested kill switch. The first time you need to stop an agent should never be the first time the mechanism is exercised.

Related services
AI Governance, Evals & Assurance →

Building on Guardrails & AI Policy? Let us talk.

Book a consultation →