Governance & Compliance

What controls do we need for prompt injection?

Layered defenses: separate untrusted content channels from instructions, validate structured tool outputs against schemas, use guardrail models to classify inputs and outputs, allowlist tools per context, budget per-action calls, and require human approval for irreversible actions (send email, transfer funds, delete data).

More on Governance & Compliance

Browse the full FAQ for 164 answers, or start a free GenAI maturity assessment to see where your organisation stands.