The guardrail in prose

Blog

100 articles on guardrails, granite and Brazilian compliance — short answer, key facts and sources in each one.

100articles
9categories
3languages

arquitetura · 8

arquitetura

Guardrail-as-a-service architecture

Guardrail-as-a-Service (GaaS) is a cloud-native architecture that delivers configurable, auditable AI safety controls—such as content filtering, bias…

arquitetura

Audit trail imutável

An immutable audit trail is a cryptographically secured, append-only record of system events that cannot be altered or deleted after creation—ensuring…

arquitetura

Camadas do guardrail e latência

AI guardrail layers—input validation, content moderation, output filtering, and policy enforcement—introduce cumulative latency, typically adding 15–120…

arquitetura

Integração com Claude, GPT e próprio

IBM watsonx supports integration with third-party LLMs—including Anthropic’s Claude and OpenAI’s GPT—via standardized API connectors and orchestration…

arquitetura

OpenTimestamps on Bitcoin

OpenTimestamps is a lightweight, decentralized protocol that binds digital data to Bitcoin’s immutable ledger via cryptographic timestamping—without…

arquitetura

Proof of anteriority

Proof of anteriority is cryptographic evidence that a digital artifact existed at or before a specific point in time. OpenTimestamps provides a…

arquitetura

Public receipt: endpoint without login

A public receipt endpoint without login is an API route that serves verifiable transaction receipts to unauthenticated clients, typically using…

arquitetura

WORM 7 years for regulated entities

WORM (Write Once, Read Many) storage with 7-year retention is a de facto operational requirement for many regulated entities in Brazil—not mandated by a…

compliance-br · 25

compliance-br

Medical record anonymization

Under Brazil’s LGPD (Lei Geral de Proteção de Dados), medical record anonymization is a lawful means to process health data without consent—provided it…

compliance-br

AI does not decide administrative act

Under Brazil’s Lei 14.133/2021 (the Public Procurement Law), administrative acts must be performed, justified, and signed by a human public agent — AI…

compliance-br

Client solicitation (CED art. 5º)

Client solicitation by lawyers in Brazil is strictly prohibited under Article 5º of the *Código de Ética e Disciplina* (CED) of the Ordem dos Advogados…

compliance-br

Verifiable legal citation

Recomendação OAB 001/2024 is a non-binding but authoritative guidance issued by the Ordem dos Advogados do Brasil (OAB) on the ethical use of generative…

compliance-br

Compliance as code in the legal field

Compliance as code in the legal field refers to the automation of regulatory interpretation, policy enforcement, and audit readiness through executable…

compliance-br

Legal consulting without a lawyer

In Brazil, providing legal consulting without being a licensed attorney is prohibited under Lei 8.906/1994, Art. 1º, which reserves the practice of law…

compliance-br

Sensitive health data

Under Brazil’s LGPD, sensitive health data is a special category requiring explicit consent and heightened security measures; the Federal Council of…

compliance-br

Diagnosis without CFM

Diagnosing a medical condition without direct clinical evaluation—such as physical examination, anamnesis, or complementary tests—is prohibited under CFM…

compliance-br

Public notice requires guardrail

In Brazil, public notices (avisos públicos) issued by regulated entities—especially financial institutions, health providers, and government bodies—must…

compliance-br

Prior disclosure of AI use

Under Recomendação OAB 001/2024, legal professionals in Brazil must explicitly disclose to clients the use of AI tools in service delivery—before…

compliance-br

Lei 14.133 (public procurement)

Lei 14.133/2021 is Brazil’s unified public procurement law, replacing Laws 8.666/1993 and 10.520/2002 to modernize bidding procedures, enhance…

compliance-br

Lei 8.429 (administrative misconduct)

Lei 8.429/1992 (Lei de Improbidade Administrativa) defines and sanctions acts of administrative misconduct by public agents in Brazil, including illegal…

compliance-br

LGPD and personal data in AI

Under Brazil’s LGPD (Lei Geral de Proteção de Dados, Law No. 13,709/2018), personal data used in AI systems must comply with all core…

compliance-br

LRF and the guardrail of art. 20

LRF Art. 20 establishes that public entities must adopt internal control mechanisms—including technical, administrative, and ethical guardrails—to ensure…

compliance-br

PLD/FT without customer data

Anti-money laundering (AML) and counter-terrorism financing (CFT) obligations under Lei 9.613/89 apply *regardless of whether customer data is…

compliance-br

Legal practice without OAB

In Brazil, practicing law—including drafting legal instruments, representing clients in court, or providing formal legal advice—without registration with…

compliance-br

Promising a result (CED art. 2º)

Under Brazil’s Consumer Defense Code (CED), Article 2º defines the consumer as *any individual or legal entity that acquires or uses a product or service…

compliance-br

Medical record and LGPD art. 11

Under Brazil’s LGPD (Law No. 13,709/2018), processing personal data in medical records requires a valid legal basis under Article 11—most commonly…

compliance-br

OAB Recommendation 001/2024

OAB Recommendation 001/2024 is a non-binding guidance issued by the Brazilian Bar Association (Ordem dos Advogados do Brasil) on 12 March 2024, advising…

compliance-br

Res. 2.682 and IFRS 9

Resolução 2.682/1999 do Banco Central do Brasil (BCB) establishes the regulatory framework for credit risk provisioning in financial institutions,…

compliance-br

Full review before filing (CPC 77)

Under CPC Art. 77, parties must conduct a mandatory full review of all procedural documents before filing any petition or response in Brazilian civil…

compliance-br

Judicial secrecy (CPC art. 189)

Judicial secrecy under CPC Art. 189 restricts public access to court records containing sensitive personal, financial, or investigatory data—only…

compliance-br

Bank secrecy and LC 105

Law Complementar (LC) No. 105/2001 establishes the legal framework for bank secrecy in Brazil, defining it as a qualified confidentiality regime…

compliance-br

Tax secrecy

Tax secrecy in Brazil is a constitutional principle (Art. 198 of the Federal Constitution) that prohibits the Brazilian Revenue Service (RFB) from…

compliance-br

TED OAB/SP and AI review

The TED OAB/SP (Termo de Engajamento com a Inteligência Artificial) is a voluntary, non-binding ethical framework issued by the São Paulo branch of the…

confianca · 8

confianca

Auditoria OAB/BCB/TCU

Auditoria OAB/BCB/TCU refers to independent oversight mechanisms—conducted by the Brazilian Bar Association (OAB), Central Bank of Brazil (BCB), and…

confianca

O badge Guarded by g.cloud

The *Guarded by g.cloud* badge signals that an AI solution has undergone IBM Granite-based guardrail enforcement—covering input sanitization, output…

confianca

TST e a multa de 1%

The TST (Superior Labor Court of Brazil) does not impose or administer a general “1% fine” — no such statutory or jurisprudential penalty exists in…

confianca

Confiança sem rastro não vale

Trust without traceability is not trust—it’s assumption. In AI governance, regulatory compliance, and professional accountability, verifiable provenance…

confianca

The 7 reasons to trust the guardrail

The guardrail is trusted because it’s built on deterministic, auditable logic—not opaque LLM weights—enforcing consistent, policy-aligned outputs across…

confianca

The guardrail receipt

The g.cloud receipt is public, immutable (WORM 7 years) and stamped on Bitcoin via OpenTimestamps — proof the AI was guarded.

confianca

STJ oficiou a OAB

The Superior Tribunal de Justiça (STJ) formally requested guidance from the Ordem dos Advogados do Brasil (OAB) on ethical and procedural implications of…

confianca

TJPR e as 43 decisões inventadas

The Tribunal de Justiça do Paraná (TJPR) did not issue 43 “invented” decisions — no verified record or official repository confirms the existence of such…

granite · 15

granite

Aberdeen, the Granite City

Aberdeen is nicknamed “The Granite City” due to its extensive use of locally quarried grey granite in 18th- and 19th-century architecture—over 90% of its…

granite

The etymology of granite (granum)

Granite comes from Latin granum (grain), for its crystalline texture; an igneous rock used since ancient Egypt.

granite

The geology of granite in 3 paragraphs

Granite is a coarse-grained igneous rock formed mainly from quartzo (quartz) and feldspato (feldspar), crystallized slowly from silica-rich magma deep…

granite

Granite Guardian vs proprietary guardrails

Granite Guardian is IBM’s open, modular guardrail framework for Granite LLMs—designed for transparency, customization, and compliance—whereas proprietary…

granite

The Granite Railway and steam cutting

The Granite Railway, opened in 1826 in Quincy, Massachusetts, was the first commercial railroad in the United States—and it transported granite blocks…

granite

Why granite became a metaphor for guardrail

Granite became a metaphor for AI guardrails because IBM’s Granite family of foundation models is engineered with built-in safety, reliability, and…

granite

Granite in Ancient Egypt

Ancient Egyptians quarried granite primarily from the Aswan (Assuã) region and used it for sarcophagi, columns, and casing blocks—most notably in the…

granite

Granite vs sandstone: hardness

Granite is significantly harder than sandstone: granite ranks 6–7 on the Mohs hardness scale, while sandstone typically ranges from 2 to 6.5, with most…

granite

IBM Granite: the open-weights family

IBM Granite is IBM’s family of open-weights foundation models—designed for enterprise use, released under the Apache 2.0 license, and optimized for…

granite

IBM Granite Guardian: the guardrail engine

IBM Granite Guardian is a production-ready, open-source guardrail engine designed to detect and mitigate harmful outputs—such as bias, toxicity, PII…

granite

Open-weights Apache-2.0 explained

Open-weights Apache-2.0 refers to AI models whose weights are publicly available *and* licensed under the permissive, patent-granting Apache License 2.0…

granite

Imperial Rome and granite

Imperial Rome imported granite primarily from the islands of Elba and Giglio in the Tyrrhenian Sea for elite architecture and sculpture; this…

granite

Self-hosting Granite Guardian

Granite Guardian is a *cloud-only, managed AI guardrail service*—it is not designed, documented, or supported for self-hosting. IBM explicitly delivers…

granite

Auditable sovereignty with open-weights

Auditable sovereignty with open-weights in IBM Granite refers to the ability for organizations—especially in regulated sectors like finance and…

granite

Brihadeeswarar Temple: the first granite temple

The Brihadeeswarar Temple in Thanjavur (Tanjore), Tamil Nadu, is widely recognized as the first *monumental* temple built predominantly of granite in…

guardrails · 15

guardrails

The 6 native categories of the guardrail

The six native categories of IBM’s Granite guardrails are: *harmful content*, *privacy*, *bias and fairness*, *robustness*, *transparency*, and…

guardrails

Jailbreak detection in Portuguese

Jailbreak detection in Portuguese refers to technical guardrails that identify and block prompt-based attempts to bypass safety constraints—such as…

guardrails

Guardrail for Claude, GPT, and own models

Guardrails for Claude, GPT, and proprietary AI models are runtime safety mechanisms—such as input/output filtering, content classification, and…

guardrails

Guardrail on input and output

Input and output guardrails are runtime safety controls that inspect, filter, or transform data before an AI model processes it (input) or before results…

guardrails

Model-independent guardrail

A model-independent guardrail is a safety control layer that operates outside the AI model itself—applied pre-inference, during inference, or…

guardrails

Guardrail as HTTP proxy

A guardrail implemented as an HTTP proxy is a network-layer enforcement point that intercepts, inspects, and optionally modifies or blocks requests to AI…

guardrails

Guardrail vs moderation API

Guardrails are proactive, model-integrated safety controls that prevent harmful outputs *before* generation; moderation APIs are reactive, post-hoc…

guardrails

Guardrail target latency: <50ms

Guardrail target latency under 50ms means AI safety checks must complete in less than 50 milliseconds end-to-end to avoid perceptible user delay—critical…

guardrails

What is an AI guardrail

An AI guardrail is the layer that filters every model response before it reaches a human — blocking hallucination, PII and jailbreaks.

guardrails

PII: CPF and CNPJ masking

CPF and CNPJ must be masked in non-production AI systems and logs under LGPD’s principle of data minimisation (Art. 6, III) and confidentiality…

guardrails

API gateway plugin (Kong)

Kong Gateway is an open-source, cloud-native API gateway that enforces runtime guardrails—including rate limiting, authentication, request validation,…

guardrails

One-line SDK: gcloud.guard

`gcloud.guard` is a lightweight, one-line SDK for embedding enterprise-grade AI guardrails—content safety, PII redaction, and policy enforcement—directly…

guardrails

Streaming with sliding window

Streaming with sliding window is a real-time inference optimization technique that processes sequential data in overlapping, fixed-size chunks to balance…

guardrails

The structured verdict of the guardrail

The structured verdict `{is_safe, risk_category, confidence, rationale}` is a standardized output format used in AI guardrail systems to classify content…

guardrails

Bias and discrimination in AI

Bias and discrimination in AI arise when models reflect or amplify societal inequities—through skewed training data, flawed feature engineering, or…

marketplace · 6

negocio · 7

teoria · 6

verticais · 10

verticais

Guardrail for legal practice

Legal practice in Brazil is subject to strict professional guardrails enforced by the Ordem dos Advogados do Brasil (OAB), which regulates admission,…

verticais

Guardrail for bank (BCB)

Brazil’s Central Bank (BCB) mandates AI guardrails for financial institutions under Complementary Law No. 105/2001, as reinforced by BCB Resolution No.

verticais

Guardrail for education

AI guardrails in education ensure responsible, equitable, and pedagogically sound use of generative AI—preventing hallucinations, bias amplification, and…

verticais

Guardrail for fintech

Fintechs operating in Brazil must comply with Law Complementar (LC) No. 105/2001, which establishes confidentiality obligations for financial…

verticais

Guardrail for hospital (CFM)

Hospitals in Brazil must implement AI guardrails aligned with CFM Resolution No. 2,314/2022 and LGPD Article 11, which mandates data minimization,…

verticais

Guardrail in court

A term “guardrail in court” has no formal legal definition in Brazilian procedural law or CNJ doctrine; it is a metaphorical, non-binding concept…

verticais

Guardrail for municipal government

Municipal governments in Brazil must implement AI guardrails aligned with the Fiscal Responsibility Law (LRF) and Law No. 14,133/2021 (Public Procurement…

verticais

Guardrail for insurer

Insurers in Brazil must comply with SUSEP’s AI guardrails, which require human oversight, transparency in automated decisions, and documented risk…

verticais

Guardrail in the public sector

In Brazil’s public sector, guardrails are operational and technical controls—grounded in the Fiscal Responsibility Law (LRF) and Law No. 14,133/2021—that…

verticais

Guardrail in telemedicine

A guardrail in telemedicine refers to a technical and procedural safeguard—mandated by the Conselho Federal de Medicina (CFM)—that ensures remote…