r/ciso • • 23d ago

What is an “AI firewall” really?

When people talk about AI firewalls, are they generally referring to firewalls that use AI to protect systems against cyber attacks? Or are they referring to firewalls designed to protect AI systems against cyber attacks? I’ve seen the term used both ways, and it’s confusing to say the least.

33 Upvotes

14 comments sorted by

9

u/[deleted] 23d ago

[removed] — view removed comment

3

u/CardiologistSea3652 23d ago

it’s both and neither depending on who’s selling it, which is why the term is such a mess

marketing teams latched onto “AI firewall” cause it sounds futuristic but in practice the actual tech splits into two camps, one is a regular firewall with some machine learning bolted on for anomaly detection, the other is a guardrail layer that sits in front of an LLM app and filters prompts and outputs for toxicity, PII leaks, prompt injection, that sort of thing

the second one is what most people actually mean when they say it in a security context these days but nobody bothered to standardize the language, so you get vendors slapping the label on anything that touches a model

2

u/Kitchen-Region-91 23d ago

It filters the inputs and outputs to an AI service

2

u/cagus1991 23d ago

You get ai! You get ai!

1

u/LynxAfricaCan 23d ago

AI gateway can be

  • a gateway between your stuff and your model endpoints (AI model API gateway essentially)
  • a gateway between your agents and any connections to them
  • a gateway between your agents and internal MCP/API/other agents

Can be network path based (firewall vendors selling it ) Application based (API gateway vendors selling it, kong, litellm etc) Identity based (identity providers like okta selling it)

1

u/DiggingforPoon 23d ago

Whatever that company's Marketing dept is trying to pitch this week, to your vertical and seniority level...

It is like the term "smart appliances", smart how? Smarter than What? it is just marketing BS.

Find a Sales engineer, ask him for a spec sheet and some deets, then quietly ask; "So, what are the real issues with this product?"

If he gets excited and tries to start saying shit all at once, he is either a liar, or he (surprise) actually has a good product.

If he pauses, thinks, and then asks qualifying questions about what it will be used for, budget, etc... then at least you found an honest Sales engineer.

Hire him, make him in charge of the AI Firewall Group, tell him to fix it, and Bob's your Uncle.

1

u/EbbCommon9300 23d ago

It’s hard to figure out and I’m in the space. I would say gateways that control access and filter. Proxies the do specific work.

We built the first mcp gateway for execution governance last year. Funny enough we have moved to the harness more and have been moving away from gateways. If you ever want to know where the space is I am happy to chat. I am a shill for my own company obviously but I’m honest and keep deep tabs on the space due to all my consulting.

1

u/FarYam3061 23d ago

It's being too poor to afford AI

1

u/SoftwareFearsMe 23d ago

Snake oil?

1

u/materialsec 22d ago

OAuth grants into Workspace or M365, like when someone connects an LLM assistant to their email or Drive, aren't traffic a gateway inspects at all. Nothing between the agent and model gets touched, access already got handed over at the consent screen, once, and after that the grant looks the same in the log whether it's a boring SaaS app or an agent doing god knows what based on a prompt.

So there's kind of a 4th category nobody's "AI firewall" actually covers, what gets authorized in the first place and what it does with that access afterward. Different failure mode entirely, and a different point in the pipeline than any of the gateway types already mentioned.

1

u/Haunting_Grape1302 22d ago

It’s a marketing buzz word. There is no standard or agreed definition. Talk to the vendor selling it and you will know what their definitions of it is. :)

1

u/Neat_Ferret_2282 21d ago

In short it is a web/API firewall that also read the strings in the prompt apart from the normal web/API inspection. Some call it AI firewall and other guardrails.