---
title: "AI Guardrails for Employee AI Use and Agent Checkpoints | Aona"
description: "Turn AI usage policies into practical controls. Explore Aona guardrails for supported employee prompts, files and API-integrated agent checkpoints."
canonical: "https://aona.ai/solutions/ai-guardrails/"
---

# AI guardrails. At the moment it matters.

[Workforce AI Security](https://aona.ai/solutions/)

Help people use AI with clear boundaries. Aona checks supported prompts and files against your policies, so sensitive information gets the right response before the next step.

Your policy. Supported prompts and files.

## AI guardrails pages

- [Overview](https://aona.ai/solutions/ai-guardrails/)
- [For employees](https://aona.ai/solutions/ai-guardrails-for-employees/)
- [For AI agents](https://aona.ai/solutions/ai-agent-guardrails/)
- [Guardrail types](https://aona.ai/resources/guides/types-of-ai-guardrails/)

## A rule becomes a response.

Start with the information or action at risk. Put the check where the next step can still change.

A guardrail is useful when its result changes what happens next. A detector, a policy and an enforcement point each have a job.

1. **Understand the input.** A prompt, a supported file or content submitted by your application.
2. **Check the policy.** Evaluate the content against the guardrail and context you configure.
3. **Apply the response.** Use the supported endpoint response, or enforce the API result in your application.

## Different moments. Clear boundaries.

Choose the part of AI use you need to protect.

### A person is about to share.

Apply data policies to supported prompts and files, with a response in the employee's AI experience.

[Guardrails for employees](https://aona.ai/solutions/ai-guardrails-for-employees/)

### An integration is about to continue.

Call Aona at a checkpoint you own. Use the verdict or returned redaction before your application proceeds.

[Guardrails for AI agents](https://aona.ai/solutions/ai-agent-guardrails/)

## Choose the control for the risk.

Data protection, tool permissions and human review solve different problems. See how the pieces fit together.

- [Sensitive-data guardrails](https://aona.ai/resources/guides/types-of-ai-guardrails/#sensitive-data): Control what information is shared with AI.
- [Prompt-injection guardrails](https://aona.ai/resources/guides/types-of-ai-guardrails/#prompt-injection): Keep untrusted content from becoming instructions.
- [Content and usage guardrails](https://aona.ai/resources/guides/types-of-ai-guardrails/#content-safety): Check whether a request fits the intended use.

[Explore all six guardrail types](https://aona.ai/resources/guides/types-of-ai-guardrails/)

## Connect controls to compliance.

See how a practical control contributes to a specific review.

A guardrail supports a control. Compliance also depends on the organisation, its processes, agreements and the full system in scope.

Configured policy → Supported response → Review evidence

### HIPAA and employee AI use

Patient information

Connect supported data protection and recorded policy events to your PHI review. Verify agreements, permitted use and the remaining information.

[Explore the control mapping](https://aona.ai/compliance/hipaa/)

[Work through a BAA decision](https://aona.ai/resources/guides/chatgpt-hipaa-baa-checklist/)

### GDPR and employee AI use

Personal data

Use configured data policies and covered activity to support your personal-data review. Your organisation determines lawful processing, contracts and transfer requirements.

[Explore the control mapping](https://aona.ai/compliance/gdpr/)

[Start an AI DPIA](https://aona.ai/resources/templates/ai-dpia-template/)

### EU AI Act and employee AI use

AI use and oversight

Build a clearer picture of covered AI use and policy responses. Use it within your organisation's assessment of roles, applicable obligations and oversight.

[Explore the control mapping](https://aona.ai/compliance/eu-ai-act/)

[Review your AI risk classification](https://aona.ai/resources/templates/eu-ai-act-risk-classification/)

### ISO 42001 and employee AI use

AI management

Bring supported usage controls and evidence into your wider AI management system. Policy templates contribute to the work; certification needs a broader assessment.

[Explore the control mapping](https://aona.ai/compliance/iso-42001/)

[Explore the gap analysis](https://aona.ai/resources/templates/iso-42001-gap-analysis/)

### SOC 2 and employee AI use

Control evidence

Review supported policy events alongside the controls and systems in your audit scope. Aona's own examination report and your organisation's audit are separate.

[Explore the control mapping](https://aona.ai/compliance/soc2/)

[Review Aona's assurance](https://aona.ai/trust/)

### Australian Privacy Act and employee AI use

Australian privacy

Apply configured policies to supported personal-data inputs and use recorded events in your review. Assess permitted handling, overseas disclosure and breach response separately.

[Explore the control mapping](https://aona.ai/compliance/australian-privacy-act/)

[Explore the Australian AI policy](https://aona.ai/resources/templates/ai-acceptable-use-policy-australia/)

## Your questions, answered.

### What are AI guardrails?

AI guardrails are checks and controls that help keep AI use within defined boundaries. They can evaluate input, constrain access or actions, inspect outputs, or require human review. An effective guardrail combines a clear policy, a check at the relevant point, a response to the result and evidence that the response happened.

### What does Aona provide?

Aona provides visibility into employee AI use on covered endpoints, configured policy responses for supported prompts and files, and supporting usage and policy evidence. Evaluation APIs let developers submit text or supported files at a checkpoint they control. The integration applies the API result; stateless evaluation calls do not automatically create an analytics event.

### How do guardrails relate to data loss prevention?

Data loss prevention is one guardrail category. It focuses on detecting and controlling sensitive information shared with AI. Guardrails also include application controls such as tool permissions, output validation and human approval. Aona's employee data protection is part of its Workforce AI Security platform; describing a guardrail category does not imply Aona implements every control in it.

### Can guardrails guarantee safe or compliant AI use?

No. Their effectiveness depends on the policy, detection quality, deployment coverage and the response applied. They contribute to security and compliance alongside approved tools, contracts, organisational processes and human judgment. Test representative allowed and prohibited inputs, including error paths, before expanding a rollout.

### Where can Aona process prompts?

Backend hosting and prompt processing are separate choices. Aona supports customer cloud, on-premises and Aona-managed hosting options, with supported prompt processing on the user device, in the customer's environment or on Aona-managed servers. Confirm the feature and integration configuration for your deployment. The destination AI provider has its own data handling.

## Bring a real AI use case.

Map the data, policy and supported coverage with our team.

[Book a demo](https://aona.ai/book-demo/)

[Review product options](https://aona.ai/product/compare/)

Canonical page: https://aona.ai/solutions/ai-guardrails/

