After creating an AI guardrails profile to regulate and control the use of generative AI apps across your organization so users are using them securely and responsibly, you must then add it to a Real-time Protection policy so you can apply the policy to the users across your organization.
You can also configure scanning limits and fallback action via API in case the limit exceeded or AI Security is down.
To create an AI Guardrails policy for Real-time Protection:
-
Go to Policies > Real-time Protection.
-
Click New Policy and then AI Guardrails.
-
On the Real-time Protection Policy page:
-
Source: Select the users, user groups, or organizational units you want to apply the AI guardrails policy to. Click Add Criteria to add other sources.
-
Destination: Select the traffic destination you want to apply the AI guardrails policy to.
-
Category: Choose Cloud App, and select from the following Gen AI apps.
-
Activities: Select the activities you want to moderate.
-
Post: A question/prompt that a user posts to a standalone AI application, which is any standalone gen AI app that can be accessed independently (e.g., ChatGPT, Google Gemini).
-
Response: An answer/response to the user’s question/prompt from the standalone AI application.
-
AI Post: A question/prompt that a user posts to an embedded AI assistant, which is any gen AI assistant embedded within a SaaS app (e.g., Copilot within Microsoft Word).
-
AI Response: An answer/response to the user’s question/prompt from the embedded AI assistant.
Some activities aren’t available for certain apps.
-
-
-
Profile & Action: Configure the following.
-
AI Guardrails: Choose the AI guardrails profiles you want to add to the Real-time Protection policy. You can add multiple profiles to a Real-time Protection policy.
-
Profile Action: Select the action you want Netskope to take when users trigger the policy.
-
Alert
-
Allow
-
Block
-
User Alert
If you select Block or User Alert, you can also choose a default or custom notification template to send to the end user if Netskope detects a policy violation for user coaching.
Optionally, you can click Set action for each profile to help you consolidate the profiles within your policy. For example, if you have multiple AI guardrails profiles in this policy, you can set an action for each profile. If multiple matching profiles have a different action within a single policy, Netskope takes the one with the most restrictive action.
-
-
-
Policy Name: Enter a policy name. You can only use alphanumeric characters and symbols such as underscore (_), dash (-), and square brackets ([ ]). You cannot use the greater-than (>) or less-than (<) symbols in policy names.
-
+ Policy Description: Click to add notes or information.
-
+ Email Notification: Netskope doesn’t send email-based notifications for AI guardrail events.
-
-
Status: Ensure it’s Enabled so the policy is active.

-
-
Click Save.
-
In the Move Policy window, move the AI guardrails policy based on your interpretation of the severity of the content moderation.

-
Click Save.
-
Click Apply Changes.
After creating an AI guardrails policy, you can view the matched policy alerts and events in Skope IT. To learn more: Viewing AI Guardrails Alerts.

