Treadstone Associates
Definition

What are AI guardrails?

AI guardrails are the deliberate limits placed on what an AI system is allowed to do on its own: filtering what goes in and out, restricting which tools or data it can reach, and requiring a person to approve certain actions before they take effect.

Treadstone Associates · Updated 2026

How it’s used in Canada

The Canadian Centre for Cyber Security’s primer on AI security actions names concrete guardrails rather than a single switch: sanitizing what a model is fed, isolating and protecting its system prompt, filtering and gating its output, restricting which tools and agents it can reach through role-based access controls, and validating a tool’s downstream action — a file write, a code change — before it is allowed to execute. The same primer documents a real case where a company removed human review from an AI hiring-screening tool and then had to reinstate it after unchecked bias affected hiring decisions — a guardrail removed, and then put back.

Guardrails are not always a company’s own choice. The Treasury Board’s Directive on Automated Decision-Making — binding on federal departments, not private business, but the most concrete Canadian example of a guardrail regime in force — states two of its requirements this way: “Completing, approving and publishing the final results of an algorithmic impact assessment… prior to the production of any automated decision system”, and separately: “Providing notice… that the decision will be made or assisted by an automated decision system” before it happens, plus a meaningful explanation after. Assessing risk before launch, and explaining a decision after it is made, are guardrails too — they just sit outside the system rather than inside it.

Worked example

An agent given access to a company’s email account can be scoped to draft-only for messages to external addresses, allowed to send internal messages under 50 words without review, and blocked outright from attaching a file over a set size — three different guardrails on the same tool, not one on/off switch.

Related terms

See also: what is human in the loop, what is an AI agent, why AI agents need guardrails.

Where this leads

Keeping a guardrail correct after go-live — not just switching it on once — is ai-operations’ territory.