Gen AI Proxy Governance for Policy Screening and Data Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Organizations lack visibility into the usage of generative artificial intelligence (Gen AI) applications, leading to unauthorized use and potential data breaches, with insufficient technical controls to enforce acceptable use policies and trace Gen AI-generated content.
Innovation Solution
A governance and data protection mechanism that integrates with Gen AI applications, providing a user interface to screen inputs and outputs based on predefined policies, categorizing them as 'allow', 'block', or 'ask', and logging interactions to ensure policy compliance and traceability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If Gen AI applications are deployed without governance controls, then productivity and user experience are improved, but data security and policy compliance deteriorate
Solution Approach 1:
A governance mechanism is introduced as an intermediary layer between users and Gen AI applications. This mechanism intercepts user inputs, screens them against security policies, and controls access to Gen AI applications, thereby maintaining productivity while ensuring data security and compliance without requiring changes to the Gen AI applications themselves
2Reliability
If strict policy controls are implemented, then data security is improved, but ease of operation and user experience deteriorate
Solution Approach 1:
The governance mechanism operates autonomously by automatically screening inputs and outputs against predefined security policies without requiring user intervention. The system self-manages policy enforcement, logging interactions and making allow/block decisions automatically, thereby maintaining ease of operation while ensuring data security
3Reliability
If comprehensive logging and monitoring are implemented, then policy compliance is improved, but device complexity and deployment difficulty increase
Solution Approach 1:
Security policies, logging templates, and monitoring configurations are predefined and prepared in advance before deployment. The governance mechanism is pre-configured with policy rules and compliance requirements, eliminating the need for complex real-time policy formulation and reducing deployment complexity while maintaining comprehensive compliance monitoring
Data Source
AI summary
A method for governing a generative artificial intelligence (Gen AI) application interaction. Input destined to a Gen AI application via a user interface is received and temporarily stored in a proxy. A policy screening is applied on the input for categorizing the input into one of ‘allow’, ‘ask’ and ‘block’ categories. At least one policy enforcement action is performed depending on the categorization of the input, the policy enforcement action resulting either releasing the input from the proxy to the Gen AI application or blocking the input from being forwarded to the Gen AI application. All interaction with Gen AI is logged.


