Category
What is AI Runtime Interaction Control?
The control that applies while an AI is being used — not beforehand in a policy and not afterwards in a report. Gartner describes four layers for AI TRiSM; this is one of them.
Four terms, one field
The category has no settled name yet. These four terms are used for the same gap, and they are the ones buyers actually type.
AI TRiSM
Gartner's framework for trust, risk and security management of AI. It classifies and names layers; it is not a product category label.
AI Runtime Inspection and Enforcement
The layer name inside AI TRiSM that describes this function: oversight, detection and defence during operation.
AI DLP
The term buyers with a DLP background use. It hits the purpose and misleads, because classical DLP inspects files and channels, not conversation state.
AI firewall
The term that conveys the role best: something sits in front and decides. Technically it is not a network firewall — the decision is about content, not connections.
The four layers, and where this control sits
Gartner describes four layers for AI TRiSM. The mapping below says what each one does and how a runtime control relates to it.
- 01
AI Governance
Accountability for AI use, alignment with regulation and business goals. Adjacent. A runtime control supplies the evidence governance works from — it does not write the policy framework.
- 02
AI Runtime Inspection and Enforcement
Real-time oversight, detection and defence during operation. The home layer. Classification, masking, routing and enforcement, per prompt and before the model.
- 03
Information Governance
Data integrity, classification, access control. Second layer. 23 PII categories across seven groups, reversible masking, token mapping inside your own environment.
- 04
Infrastructure and Stack
Operation across different environments. Third layer, and the one the delivery variants sit in: certified appliance, customer hardware to spec, or virtual platform to spec.
What it is not
Not endpoint DLP
Microsoft's documentation lists four device-side prerequisites for prompt detection in DSPM for AI: an Edge configuration policy, device onboarding, Endpoint DLP and a browser extension. Network-side inspection is listed as preview. A runtime control on the network depends on none of them.
Not a gateway in someone else's network
A service that inspects prompts inside the provider's infrastructure relocates the trust instead of evidencing it. The boundary sits where you draw it.
Not a governance tool without enforcement
A policy that does nothing at runtime is a document. The difference between oversight and control is whether a request can be stopped.
Where this classification comes from
The primary text, Gartner's Market Guide for AI TRiSM 2025, is paywalled and not available to us. The four layers and their names are consistently evidenced across five independent secondary sources, retrieved 2026-09-07: dope.security, Palo Alto Networks Cyberpedia, Mindgard, AvePoint and ModelOp. Agreement across five sources carries a classification; it is not a substitute for a citation. This page therefore claims no rating and no inclusion in a Gartner report — it places a category.
