Rules for what goes in
What must never enter an AI tool: customer records, credentials, anything under NDA. Cheap, written down, and the single most breached rule in practice.
Three words, one job. What matters is whether they still hold.
The AI conversation uses three words for the things that stand between a risk and the damage: guardrails, controls and safeguards. This page untangles them, and covers the part that matters more than the vocabulary: most of yours were built for a world that has moved.
AI guardrails are the technology industry's word, and in its home usage it means something specific: constraints designed into or around an AI system so it behaves within bounds, content filters, permission limits, restricted actions, human approval gates. When an AI vendor says guardrails, this is usually what they mean.
Controls is the risk and audit profession's word, older and broader: any measure that modifies a risk, whether it prevents, detects or corrects. If your auditors, regulators or GRC tooling use it, they mean this.
Safeguards is the plain-English word for the same job, and it is the one we use at Drova, because the people who own business objectives should not need an audit glossary to read their own risk register. On this page and across our series on the real risks of AI for a business, safeguard means: something deliberate standing between a risk and the objective it threatens.
The vocabulary matters less than people fear. What matters is the question the next section answers: what do AI-era safeguards actually look like, and do yours still hold?
What must never enter an AI tool: customer records, credentials, anything under NDA. Cheap, written down, and the single most breached rule in practice.
AI output that reaches a customer, a regulator or a decision is verified by a named person first. Accountability is a safeguard, and it stays human.
Callbacks on known numbers, out-of-band verification, dual approval with no urgency exceptions. These hold whether or not a fake is detectable.
A cadence measured in months, because AI-era safeguards age faster than the annual cycle that reviews them.
The quiet failure
A safeguard rarely fails loudly. It fails by continuing to exist after the assumption underneath it has died. Staff trained to spot scam emails by their clumsy grammar are still trained; the grammar is now perfect. Recognising a supplier's voice on the phone still feels like verification; the voice can now be manufactured. The register shows a healthy safeguard against every risk, and several of them are load-bearing paint.
This is why AI disruption is hard to see from inside: nothing on the page changed. The honest exercise is to re-read each safeguard and ask what it assumes. If the assumption is that forgery is expensive, that fluency signals legitimacy, or that speed means a human did it, the safeguard needs rebuilding on process instead. The fraud page shows this pattern in its sharpest form.
Two conversations
The guardrails conversation in the technology press is mostly about systems: filters and bounds built around models by the people who deploy them. That conversation is real, and if you are building or embedding AI products it is yours; government cyber security agencies publish guidance on it, including the Australian Cyber Security Centre.
Most businesses need the other conversation first: the safeguards around how AI is used and how it changes existing risks. Those are policy and process, not engineering, an AI policy your people actually read, and the four families above applied to the risks you already carry. Start there; add system-level guardrails when you run systems that need them.
On the register
A safeguard that lives in a policy document nobody opens is a hope. The working home for every safeguard is your risk register, attached to the specific risk it holds back, with an owner and a review date, so that when the risk is re-scored the safeguard is re-read with it.
That pairing is the whole discipline: risk moves, safeguard checked. The assessment exercise is where both get their honest re-reading, and it is also where the quiet failures from the section above actually get caught.
In the technology industry's usage: constraints designed into or around an AI system so it behaves within set bounds, content filters, permission limits, restricted actions and human approval gates. In looser business usage the word covers any protection against AI-related risk, which is where it blurs into controls and safeguards.
Mostly the room the word comes from. Guardrails is the technology world's term, usually for system-level constraints on AI behaviour. Controls is the audit and risk profession's term for any measure that modifies a risk. In practice a company's AI guardrails and its AI controls largely describe the same set of protections.
A short AI policy people actually read; a list of what never goes into AI tools; named human verification of AI output that reaches customers or decisions; callbacks and out-of-band checks for payments; dual approval with no urgency exceptions; and a review cadence in months rather than years.
Mostly you inherit them from your vendors, and your leverage is choosing tools with sensible bounds and configuring the permissions you are given. Your own work concentrates on use: policy, data rules, verification and process. If you embed AI in your own product, the system-level conversation becomes yours too.
Every three to six months, and immediately after any risk they support is re-scored. The failure mode is not usually a missing safeguard but a stale one, still on the register, resting on an assumption AI has removed.
The AI Disruption Index scores the risks AI is driving against your objectives and drafts a safeguard for each. Free, in about ten minutes.
AI risk series
The real risks of AI for a business
The series hub: what counts as an AI risk, the four families, and where to start.
How to run an AI risk assessment
Three ways to do it, compared, and the five steps.
The AI risk register
What every entry carries, with worked examples.
The AI policy your business actually needs
The full template, free on the page, and how to make it yours.
Fraud no longer needs a forger
Deepfakes, voice clones, invoice fraud, and the safeguards that still hold.
What is AI disruption?
A plain definition: the change is in your risks and plans, not just your tools.
AI in risk management: what it can genuinely do
The four jobs AI does well, and the three things it must never own.
Prompt injection: the attack your register hasn't heard of
Instructions hidden in ordinary content, and the safeguards that limit the damage.
See your own AI risk picture
The risks AI is driving against your objectives, scored for your business.