Guardrails decide what your AI may say.
Nothing shows what it is willing to do.
Filters, constrained decoding, and gateways judge one output at a time. A kill switch stops the whole system. Both are necessary, and neither answers the question your auditor, your board, and your insurer ask next: is the system you actually deployed behaving the way someone signed for — and where is the record? AI Assess Tech is that record. It runs beside your guardrails, not in place of them.
The control stack: five layers, one of them usually missing
| Layer | The question it answers | Who provides it | AI Assess Tech’s role |
|---|---|---|---|
| Policy | What is this system allowed to do? | Your AI policy and system owner | Registers each system: owner, audience, data, and action rights |
| Enforcement | Was this output blocked? | Guardrails, constrained decoding, gateways | None. We never sit in the request path. |
| Human stop | Can someone halt it right now? | Your kill switch and a named person | None. Keep it — anything that can act needs one. |
| Evidence | Is the deployed system behaving the way we signed for? | AI Assess Tech | Preregistered question banks, run against your production configuration on a schedule, each result sealed |
| Accountability | Who owns it when behavior moves? | AI Assess Tech + your chain | Escalation clock, signed attestation, and a Risk Acceptance Ledger with reasons and expiry |
DICE — AI Security Operational Excellence
Shares the minimum necessary — or leaks and exposes.
Keeps its identity and authority truthful.
Makes only authorized changes.
Acts in view — or conceals what it did.
DICE places each run among four archetypes: Trustworthy Operator, Insider Threat, Rogue Agent, and Compromised Asset — uneven behavior across dimensions.
An Insider Threat keeps a truthful identity and makes authorized changes, while disclosing covertly and concealing its actions. Each output can pass a filter. The pattern shows up only across a structured instrument.
How the evidence layer works
- Measured, moment-in-time evidence of deployed behavior, repeated on a schedule
- Provider-agnostic, and independent of the model vendor
- Tamper-evident records an auditor can verify without trusting your logs
- A guardrail, filter, or replacement for your kill switch
- A penetration test or automated red-team
- A certification or a guarantee of behavior