Cisco has added Policy Studio to AI Defense, a guided authoring tool that lets enterprise compliance teams translate plain-language rules into enforceable AI guardrails without writing code or configuring regex fields.
The feature, described by Cisco's AI Defense engineering team, targets a gap in enterprise AI governance. A retail bank's AI assistant should answer "how does a 401(k) work" but under SEC and FINRA rules may not be able to provide personalized investment advice. Today's tools ask the policy owner to write that distinction from scratch. Policy Studio replaces that blank-page problem with a conversational session: an AI agent asks targeted questions about what the rule should mean, pairs each question with evidence from the organization's own production chat logs, and rewrites the draft on each resolved answer. The finished guardrail is published directly to the Cisco AI Defense runtime enforcement console.
Cisco's design draws on Constitutional AI research. The company's Cisco AI Defense shared safety taxonomies already run 300-plus lines per technique, precise enough that multiple frontier models reach the same decision on the same input. Policy Studio applies that same constitutional method to organization-specific rules. At runtime, an open-source policy-aware safety model such as Meta's Llama Guard, Google's ShieldGemma, or NVIDIA's Aegis Safety Guard reads the document directly at inference. Cisco says this lets enterprises enforce custom guardrails without a hosted API dependency.
Policy Studio surfaces two types of issues during authoring. Textual insights flag gaps or ambiguous clauses in the draft itself. Behavioral insights come from running the current draft against production logs and grouping flagged cases by the reasoning path that produced them; a single answer from the policy owner applies to every conversation in the group. A policy with ten distinct decisions takes roughly ten resolved insights whether the organization has 70 or 70,000 example chats, according to Cisco.
Policy Studio publishes directly to the Cisco AI Defense guardrails console, running alongside the platform's published safety taxonomies. For enterprises already running Cisco AI Defense, the new tool extends the same enforcement layer to domain-specific policies without requiring a separate governance product. Cisco has not yet stated a general availability date. A forthcoming arXiv technical paper will cover the system's design, the company said.
The launch arrives as auditors and regulators increasingly ask organizations to show that AI guardrails correspond to documented, reviewable policy rather than informal prompt instructions. Cisco's framing collapses two previously separate processes: the compliance document that legal teams recognize and the runtime enforcement rule the language model reads.













