Skip to content

Cisco Adds Policy Studio to AI Defense, Letting Enterprises Write Custom AI Guardrails in Plain Language

Cisco launched Policy Studio inside AI Defense, a guided authoring tool that converts compliance teams' plain-language rules into enforceable AI guardrails backed by constitutional AI research.

Cisco AI Defense Policy Studio interface showing Policy Studio Assistant and policy details panel
Credit: Cisco

Cisco has added Policy Studio to AI Defense, a guided authoring tool that lets enterprise compliance teams translate plain-language rules into enforceable AI guardrails without writing code or configuring regex fields.

The feature, described by Cisco's AI Defense engineering team, targets a gap in enterprise AI governance. A retail bank's AI assistant should answer "how does a 401(k) work" but under SEC and FINRA rules may not be able to provide personalized investment advice. Today's tools ask the policy owner to write that distinction from scratch. Policy Studio replaces that blank-page problem with a conversational session: an AI agent asks targeted questions about what the rule should mean, pairs each question with evidence from the organization's own production chat logs, and rewrites the draft on each resolved answer. The finished guardrail is published directly to the Cisco AI Defense runtime enforcement console.

Cisco AI Defense video thumbnail shows the enterprise security platform
Security for AI: Cisco AI Defense in Action. Video: Cisco via YouTube.

Cisco's design draws on Constitutional AI research. The company's Cisco AI Defense shared safety taxonomies already run 300-plus lines per technique, precise enough that multiple frontier models reach the same decision on the same input. Policy Studio applies that same constitutional method to organization-specific rules. At runtime, an open-source policy-aware safety model such as Meta's Llama Guard, Google's ShieldGemma, or NVIDIA's Aegis Safety Guard reads the document directly at inference. Cisco says this lets enterprises enforce custom guardrails without a hosted API dependency.

Policy Studio surfaces two types of issues during authoring. Textual insights flag gaps or ambiguous clauses in the draft itself. Behavioral insights come from running the current draft against production logs and grouping flagged cases by the reasoning path that produced them; a single answer from the policy owner applies to every conversation in the group. A policy with ten distinct decisions takes roughly ten resolved insights whether the organization has 70 or 70,000 example chats, according to Cisco.

Policy Studio publishes directly to the Cisco AI Defense guardrails console, running alongside the platform's published safety taxonomies. For enterprises already running Cisco AI Defense, the new tool extends the same enforcement layer to domain-specific policies without requiring a separate governance product. Cisco has not yet stated a general availability date. A forthcoming arXiv technical paper will cover the system's design, the company said.

The launch arrives as auditors and regulators increasingly ask organizations to show that AI guardrails correspond to documented, reviewable policy rather than informal prompt instructions. Cisco's framing collapses two previously separate processes: the compliance document that legal teams recognize and the runtime enforcement rule the language model reads.

Share this story

Julian Beaumont

Julian Beaumont covers artificial intelligence and large language models for techshooked, following the path from research paper to deployed feature. His standard is anti-hype: ask what a model actually does, what trained it, how it fails, and whether a benchmark measures what the announcement claims.