Continue normally
The DLP service allows the content. AI Warden still applies native AI policies, budgets, model routing, MCP controls and request logging.
Platform · ICAP / DLP
AI Warden can call ICAP-supported DLP platforms, including common enterprise DLP and SSE inspection services where supported, before AI requests leave and before responses return. Your DLP outcomes can allow, modify, block or trigger session-level controls according to policy.
Request and response enforcement
AI risk is bidirectional. Users can send sensitive data to a model or tool, and models or tools can return content that should not be delivered. AI Warden gives ICAP inspection points on both sides.
Inspection lifecycle
AI Warden can sit between employees, apps, hosted agents, LLM providers and MCP servers. The gateway resolves identity and policy, sends the relevant body and context to ICAP where configured, applies the DLP decision, then continues with AI Warden scanners, routing and audit.
1. receive user prompt / upload / MCP tool call 2. resolve user · agent · provider · MCP server · policy 3. inspect request allow | modify | block | error 4. enforce block, forward modified body, or continue 5. upstream LLM provider or MCP server 6. inspect response review generated response or tool result 7. deliver allowed/modified content or policy denial 8. audit request log with inspection outcomes
AI-aware actions
A hosted chatbot receiving a file upload can send that content to ICAP. If the DLP response is modify or block, AI Warden can decide what happens next in the AI experience.
The DLP service allows the content. AI Warden still applies native AI policies, budgets, model routing, MCP controls and request logging.
Deliver the modified body, warn the user, remove sensitive content, or disable selected tools such as internet search, external connectors or file export for that session.
End the chat session, block the tool call, quarantine an agent, require approval, notify SOC, or auto-disable a risky user or agent after repeated events.
Fail-safe default
For regulated enterprises, an unavailable inspection path should not silently become no inspection. AI Warden can treat ICAP timeouts, connection failures, malformed responses and configured body-size violations as deny outcomes, with audit detail for the failed inspection attempt.
Behaviour-based controls
AI Warden knows the authenticated user, delegated user, hosted agent, MCP server, provider, model and session behind each event. That makes it possible to act on patterns, not just individual blocks.
Example action: disable internet search for the active session, notify SOC and route the agent owner through review.
Audit evidence
Request logs can retain the gateway outcome, AI Warden policy outcome, ICAP request decision, ICAP response decision, service status, latency, flags, principal, delegated user, agent and target system.
traffic_type: mcp principal: aiwadmin agent: aiw-demo-customer-insights-assistant tool: customer_profile_export icap.request: allow · 204 · 24ms icap.response: blocked · 200 · 31ms action: disable external export tools for session outcome: denied before client delivery evidence: queryable · exportable
Use your DLP investment
AI Warden does not ask regulated customers to trust a separate AI-only policy layer instead of their DLP programme. It lets both operate in the request path, with configurable fail-closed enforcement and AI-aware session actions.