AI Guardrails Are Not Access Controls: CyberQP CEO
Guardrails are only intended for the LLMs to ‘understand what they’re generating’—not to ensure that the right people have the right level of access privileges, says CyberQP CEO Mateo Barraza.
The safety and security guardrails built into widely used AI models do not include—and should not be mistaken for—the access controls that organizations need to protect their IT systems and data, according to Mateo Barraza, co-founder and CEO of zero-trust access management vendor CyberQP.
Put simply, “guardrails are not access controls,” Barraza said during a session Tuesday at XChange August 2026, which is hosted by CRN parent The Channel Company and being held this week in National Harbor, Md.
[Related: Huntress CEO: The Autonomous Adversary Is Here And ‘We've All Been Drafted’]
“Guardrails are for the large language models to actually understand what they’re generating—[such as] if they’re generating something that’s malicious or that could be hurtful to society or to human beings,” he said during the session at the conference.
On the other hand, access controls are used to “control the flow of data to make sure that the right people have the right data access,” Barraza said.
The two can be conflated, however, because the assumption can sometimes be made that providers of general-purpose LLMs are building such controls into their models, he noted.
Without a doubt, Barraza is making an important point by focusing on what AI guardrails are—and are not—actually meant to provide in terms of security, said Michael Tanenhaus, president and CEO of Annapolis, Md.-based Mavenspire.
“When AI companies talk about what a guardrail is, they are not talking about evaluating whether someone should have privileged access,” Tanenhaus told CRN.
CyberQP also seems to be on the right track by emphasizing that “we need a different model for how that gets done,” he said.
CyberQP has taken that approach with a purpose-built AI architecture for privileged access management and identity governance, CyberQP executives said during the session Tuesday.
“The AI never touches your privileged credentials. And so, what we have done is we’ve created a custom AI harness that mediates every action,” said Jim Jessup, co-founder and COO of CyberQP, during the session. “The model never receives raw secrets. So we have a clear separation.”
There’s no question that a separate security layer is essential, as organizations increasingly provide AI agents with the ability to take action across their IT environments, according to Tanenhaus.
“If you think about all the companies that have come out with API security gateways—[CyberQP] is basically saying that’s what we need to do in AI. We need to figure out a way to say the AI can execute something, but it needs to talk to a gateway,” he said. “They’re definitely on the leading edge of what they do.”