Gen AI Proxy Governance for Policy Screening and Data Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations lack visibility into the usage of generative artificial intelligence (Gen AI) applications, leading to unauthorized use and potential data breaches, with insufficient technical controls to enforce acceptable use policies and trace Gen AI-generated content.

Innovation Solution

A governance and data protection mechanism that integrates with Gen AI applications, providing a user interface to screen inputs and outputs based on predefined policies, categorizing them as 'allow', 'block', or 'ask', and logging interactions to ensure policy compliance and traceability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If Gen AI applications are deployed without governance controls, then productivity and user experience are improved, but data security and policy compliance deteriorate

Engineering Contradiction:
ImproveGen AI application usageVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

A governance mechanism is introduced as an intermediary layer between users and Gen AI applications. This mechanism intercepts user inputs, screens them against security policies, and controls access to Gen AI applications, thereby maintaining productivity while ensuring data security and compliance without requiring changes to the Gen AI applications themselves

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If strict policy controls are implemented, then data security is improved, but ease of operation and user experience deteriorate

Engineering Contradiction:
Improvedata securityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The governance mechanism operates autonomously by automatically screening inputs and outputs against predefined security policies without requiring user intervention. The system self-manages policy enforcement, logging interactions and making allow/block decisions automatically, thereby maintaining ease of operation while ensuring data security

Inventive Principle:
Principle #25Self-service

3Reliability

If comprehensive logging and monitoring are implemented, then policy compliance is improved, but device complexity and deployment difficulty increase

Engineering Contradiction:
Improvepolicy complianceVSAvoidgovernance mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Security policies, logging templates, and monitoring configurations are predefined and prepared in advance before deployment. The governance mechanism is pre-configured with policy rules and compliance requirements, eliminating the need for complex real-time policy formulation and reducing deployment complexity while maintaining comprehensive compliance monitoring

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20260037617A1Governance and data protection in use of generative artificial intelligence
Publication Date: 2026.02.05 NROC SECURITY OY
  • US20260037617A1 patent drawing
  • US20260037617A1 patent drawing
  • US20260037617A1 patent drawing

AI summary

A method for governing a generative artificial intelligence (Gen AI) application interaction. Input destined to a Gen AI application via a user interface is received and temporarily stored in a proxy. A policy screening is applied on the input for categorizing the input into one of ‘allow’, ‘ask’ and ‘block’ categories. At least one policy enforcement action is performed depending on the categorization of the input, the policy enforcement action resulting either releasing the input from the proxy to the Gen AI application or blocking the input from being forwarded to the Gen AI application. All interaction with Gen AI is logged.