A readable policy
Every tool call is classified, then settled by a written, versioned, reviewable rule. A language model does not arbitrate authorisations: it is consulted only on ambiguous cases, and never to lift a prohibition.
xSOM AI Guard
An agent that writes text creates a text risk. An agent with tools deletes, pays, sends, writes to production. xSOM AI Guard sits between the agent and its tools, and decides — call by call — what goes through, what waits for a human, and what will not happen.
The shift
Most guardrails look at what the model is told, or at what it answers. That is useful, and insufficient: the damage does not happen in the sentence, it happens the moment the agent calls a tool.
Control therefore has to apply to the action. Deleting a contact, moving money, shipping a release, writing into a client system: those are decided before they are executed, not after they have been described.
It is the only place where a refusal is still a refusal.
The mechanism
Every tool call is classified, then settled by a written, versioned, reviewable rule. A language model does not arbitrate authorisations: it is consulted only on ambiguous cases, and never to lift a prohibition.
An irreversible action is held, shown as a dry run — what it would do, and to what — then executed only once approved. Not approved means it does not happen. The block is held by the gateway, never delegated to the model.
Every decision is append-only and hash-chained: altering one line breaks the chain, and the break is visible. The exports serve a demonstration of compliance rather than a promise of it.
And the rule that holds all three: when in doubt, refuse. Unknown tool, approval service unreachable — on anything irreversible, no answer means refusal, never permission.
Sitting in the path
The difference is not an integration detail: it decides whether a refused action can still happen.
The agent's tools go through the gateway. It executes, or it does not. This is the only path where the refusal does not depend on the agent's goodwill.
For an agent whose code you own: a few lines that ask for a verdict before acting. The guarantee is worth exactly what the agent honouring it is worth.
One change of base URL, no code touched. Binding on what leaves — which is already a great deal when the agent's code is not yours.
Where the product stands
xSOM AI Guard is a product under construction, built by the firm. The foundation is working and tested — gateway, policy, human approval, chained log — and that is what the demonstration shows.
What it does not do, it does not claim: it is not a prompt-injection detector, not a personal-data filter, and not a sovereign hosting offer. Those belong to our consulting work, not to this tool.
The demonstration is given under named access, by appointment: we show an agent attempting an irreversible action, the hold, the refusal, and the fact that the action did not happen.
Next step
Tell us which tools they touch and what keeps you up at night. We will show you what putting them under control would change, on your own case.