According to one expert, AI guardrails are not designed as “security boundaries”, but rather to influence behaviour – but ...
Any data that enters your system from outside a trust boundary should be treated as untrusted until proven otherwise. That includes form fields, API payloads, file uploads, headers, cookies, queue ...