Why Aggrete built AI governance using deterministic rules, not AI models
Aggrete, a platform governing AI assistant actions across HR, finance, Slack, and code, deliberately excluded AI models from its security decision layer. Instead of using a guard model to classify requests as safe or unsafe, the system relies entirely on deterministic, rule-based logic. The team found that LLM-based guards are non-deterministic, meaning identical inputs can yield different outputs across time, making audit trails and compliance defenses unreliable. Deterministic rules also resist prompt-injection attacks, since they evaluate structured state rather than natural language that can be manipulated. Critically, stateful rules allow the system to detect risk spread across multiple individually harmless requests — something a stateless model judge structurally cannot do.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in