Recommended guardrail
Bound every AI workload's steps, tokens, and spend, and alert on anomalies
Cap agent loop iterations and tool calls, set per-key and per-project spend limits, alert on anomalous usage, and scope and rotate model credentials. Detect agent loops with no step limit and model calls with no budget or rate guard.
This is TwinEthos's opinion of what a responsible AI integration does anyway. It is never a legal or standards requirement; where binding law applies, the law governs.
The recommended-guardrail rule files are open under CC BY 4.0; attribution and scope are in the terms.
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.
Evidence grade
Recommended by 1 standard
1 standard or framework · 1 graded incident.
TwinEthos recommendation, not law. Where binding law applies, the law governs. No binding law in the corpus requires this control yet. 1 standard or framework recommends it (NIST AML Taxonomy (AI 100-2e2025) — Agentic). 1 graded incident cited.
Standards and frameworks
- GenAI services should restrict per-user query volume and user-controlled inference parameters (NIST AI 100-2e2025) (NIST AML Taxonomy (AI 100-2e2025) — Agentic; NIST AI 100-2e2025, Sec. 3.3.3 (Mitigations: usage restrictions) and Sec. 3.4.1 (Availability Attacks: time-consuming background tasks); same control)
Family “AI controls are not preserved under cost, latency, or model-change pressure”: binding law on related controls is in force in no jurisdiction. Context only: it does not change this guardrail's grade.
Graded incidents
- LLMjacking: stolen cloud credentials used to consume hosted LLMs (2024-05; confirmed) Sysdig Threat Research Team (original researcher disclosure) · evidence grade: primary
The guard to add
Cap agent steps and output tokens on every model call, set per-key and per-project budgets with usage alerts, and issue scoped, expiring model keys.
Bound work at three layers. In code, every agent or tool-use loop has a hard step cap (a counted for loop, max_iterations, recursion_limit, maxSteps or stopWhen) and every user-triggered call sets an output-token cap. At the gateway or provider, each key and team has a budget and rate limits (max_budget, budget_duration, tpm_limit, rpm_limit), and keys are scoped to the models and project that need them and expire on a rotation schedule. In the infrastructure that provisions the model account, a cloud budget with alert notifications surfaces anomalous spend to the owning team.
Example (Python agent loop + OpenAI SDK), before:
while True:
resp = client.chat.completions.create(model=MODEL, messages=msgs, tools=TOOLS)
msg = resp.choices[0].message
if not msg.tool_calls:
break
msgs += [msg, *run_tools(msg.tool_calls)]After:
MAX_STEPS = 10
for step in range(MAX_STEPS):
resp = client.chat.completions.create(model=MODEL, messages=msgs, tools=TOOLS,
max_completion_tokens=1000)
msg = resp.choices[0].message
if not msg.tool_calls:
break
msgs += [msg, *run_tools(msg.tool_calls)]
else:
raise StepLimitExceeded(f'agent stopped after {MAX_STEPS} steps')Control: AI usage, agent steps, and spend not bounded. Engineering guidance, not legal advice.
Why
Agent loops and exposed keys can turn model spend into an open-ended cost. Sysdig's researchers reported stolen cloud credentials used to consume hosted models at the account owner's expense; the controls that limit the damage (spend caps, usage alerts, scoped keys) are cheap to add and easy to forget.
Class: operational integrity · set: operational integrity · maturity: reviewed · confidence: medium · id guardrail.opint-bounded-spend-and-usage