A field guide to AI positions

Guardrails

Publication dates and source age

Sources counted: 2

Newest dated source: 2025-03-24

At least one source was published within the 18-month window.

Assessed at this edition's evidence cutoff: 2026-09-15. 18-month boundary: 2025-03-15.

Some publication dates are unknown; the newest dated source may not be the newest source overall.

Publication age does not tell us whether a claim is still valid. Reading an old source again does not make its publication date newer. An update date does not establish that the passage we used was updated.

Open in the glossary Reading notes · Structured record

In plain language

Checks and restrictions intended to prevent unwanted inputs, outputs or actions in an AI application. [1]

Reference this explanation or suggest a correction

Link to this explanation · Suggest a correction · How corrections work

Limits & distinctions

A check on the final answer does not itself restrict an earlier tool action. Stating that guardrails exist does not establish their effectiveness against the relevant attacks. [1] [2]

Reference this explanation or suggest a correction

Link to this explanation · Suggest a correction · How corrections work

A fuller explanation

The term covers different controls. A concrete implementation may check user input, filter retrieved documents, inspect a reply or validate a tool call before execution. The control's location matters. [1]

Reference this explanation or suggest a correction

Link to this explanation · Suggest a correction · How corrections work

How it relates to the map

Atlas reading question: which safeguard is actually enforced, at which step, and against which failure? [1]

Reference this explanation or suggest a correction

Link to this explanation · Suggest a correction · How corrections work

Share this page

https://theaiatlas.org/ideas/guardrails/

Download a share image · Vector image

Image previews are summaries. Keep the page link so readers can check the evidence.

Sources and what we read

  1. 1. Guardrail Types

    Publication dates and source age

    Sources counted: 1

    Publication dates are unavailable.

    Assessed at this edition's evidence cutoff: 2026-09-15. 18-month boundary: 2025-03-15.

    Some publication dates are unknown; the newest dated source may not be the newest source overall.

    Publication age does not tell us whether a claim is still valid. Reading an old source again does not make its publication date newer. An update date does not establish that the passage we used was updated.

    Read the descriptions and tables of input, retrieval, dialog, execution and output rails. Used as a concrete implementation example of the broader term. No publication date is displayed; the security FAQ link returned 404 and was not used.

  2. 2. Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations

    Publication dates and source age

    Sources counted: 1

    Newest dated source: 2025-03-24

    At least one source was published within the 18-month window.

    Assessed at this edition's evidence cutoff: 2026-09-15. 18-month boundary: 2025-03-15.

    Publication age does not tell us whether a claim is still valid. Reading an old source again does not make its publication date newer. An update date does not establish that the passage we used was updated.

    Read the executive summary, attack-stage definitions, and sections 3.2.1 to 3.2.3 on generative-model poisoning and mitigations. Publication date comes from the NIST publication record. No claim is made that one defense stops all attacks.

Edition and machine-readable evidence

Content version 0.20.0. Evidence cutoff 2026-09-15; this does not mean every source was read on that day.

Pinned complete dataset · Complete evidence page · Agent consumption guide