Skip to main content

Category

What is AI Runtime Interaction Control?

The control that applies while an AI is being used — not beforehand in a policy and not afterwards in a report. Gartner describes four layers for AI TRiSM; this is one of them.

Four terms, one field

The category has no settled name yet. These four terms are used for the same gap, and they are the ones buyers actually type.

  • AI TRiSM

    Gartner's framework for trust, risk and security management of AI. It classifies and names layers; it is not a product category label.

  • AI Runtime Inspection and Enforcement

    The layer name inside AI TRiSM that describes this function: oversight, detection and defence during operation.

  • AI DLP

    The term buyers with a DLP background use. It hits the purpose and misleads, because classical DLP inspects files and channels, not conversation state.

  • AI firewall

    The term that conveys the role best: something sits in front and decides. Technically it is not a network firewall — the decision is about content, not connections.

The four layers, and where this control sits

Gartner describes four layers for AI TRiSM. The mapping below says what each one does and how a runtime control relates to it.

  • 01

    AI Governance

    Accountability for AI use, alignment with regulation and business goals. Adjacent. A runtime control supplies the evidence governance works from — it does not write the policy framework.

  • 02

    AI Runtime Inspection and Enforcement

    Real-time oversight, detection and defence during operation. The home layer. Classification, masking, routing and enforcement, per prompt and before the model.

  • 03

    Information Governance

    Data integrity, classification, access control. Second layer. 23 PII categories across seven groups, reversible masking, token mapping inside your own environment.

  • 04

    Infrastructure and Stack

    Operation across different environments. Third layer, and the one the delivery variants sit in: certified appliance, customer hardware to spec, or virtual platform to spec.

What it is not

  • Not endpoint DLP

    Microsoft's documentation lists four device-side prerequisites for prompt detection in DSPM for AI: an Edge configuration policy, device onboarding, Endpoint DLP and a browser extension. Network-side inspection is listed as preview. A runtime control on the network depends on none of them.

  • Not a gateway in someone else's network

    A service that inspects prompts inside the provider's infrastructure relocates the trust instead of evidencing it. The boundary sits where you draw it.

  • Not a governance tool without enforcement

    A policy that does nothing at runtime is a document. The difference between oversight and control is whether a request can be stopped.

Where this classification comes from

The primary text, Gartner's Market Guide for AI TRiSM 2025, is paywalled and not available to us. The four layers and their names are consistently evidenced across five independent secondary sources, retrieved 2026-09-07: dope.security, Palo Alto Networks Cyberpedia, Mindgard, AvePoint and ModelOp. Agreement across five sources carries a classification; it is not a substitute for a citation. This page therefore claims no rating and no inclusion in a Gartner report — it places a category.