What is an Enforcement Runtime?

What is an Enforcement Runtime?
An enforcement runtime is infrastructure that sits in the send path of AI systems and enforces written rules on every output: it passes, fixes, blocks, or escalates each message before delivery, and logs the decision as evidence.
"Written rules" means regulations, company policies, and security controls. "Send path" means the runtime sits between the model and the recipient, so nothing reaches a customer, a counterparty, or another system until it has been enforced. The verdict is the unit of work. Every verdict is logged.

How it works
Four verdicts.
One of them, every time.
Pass
Clean output goes through.
Fix
Violations are fixed, then revalidated.
Block
Prohibited output never leaves.
Escalate
A person decides the edge cases.
Every message gets exactly one verdict before delivery. The verdict, the rule it cited, and any fix are written to the log as evidence.
What it is not
Adjacent tools, and where they stop.
Guardrails flag
They tell you. They don't fix.
Gateways mask
Patterns, not rules.
Archiving records
After the fact, not before.
DLP matches patterns
It can't read a regulation.
Why now
Adjacent tools, and where they stop.
$2.8B+
Off-channel communications penalties levied by the SEC and CFTC since 2021.
SEC and CFTC enforcement actions, 2021 to 2024
24-09
FINRA's 2024 notice to members: existing rules apply to AI-generated communications, including 2210 and 3110. No exemption for a message a model wrote.
FINRA Regulatory Notice 24-09, June 2024
Every company fined for off-channel communications had an archive. The archive proved what went wrong after it went wrong. AI changed the math: a single assistant can draft a compliance team's entire year of review work in a day, and none of it can wait in a queue. The rules are the same. The only place left to enforce them is the send path, at the moment of delivery. That is what an enforcement runtime is for.
FAQ
Common questions.
Is an enforcement runtime the same as AI guardrails?
No. AI guardrails detect and flag unsafe or off-policy content. An enforcement runtime goes further by checking each message against written rules and deciding what happens next. It can pass the message, fix a violation, block it, or escalate it for human review. Every decision is logged as evidence.
How is an enforcement runtime different
from an LLM gateway?
A gateway routes traffic between an application and its model providers and can mask patterns like phone numbers or card numbers. An enforcement runtime checks each output against regulations, company policies, and security controls, then returns a verdict that determines what happens to the message. The two can work together, with the gateway handling traffic and the runtime enforcing the rules.
Does an enforcement runtime replace
archiving and surveillance?
No. Archiving and surveillance provide a record of communications after they are sent. An enforcement runtime acts before delivery, stopping violations and recording the enforcement decision as evidence. It adds enforcement before the message is sent, while existing systems continue to record communications afterward.
Within the context of an enforcement runtime,
what does "Fix" mean?
When an output violates a rule, the runtime fixes the violation, then checks the updated message again before it is delivered. That could mean replacing a promissory phrase with compliant language or adding a missing disclosure. If the message passes the second check, it can be sent. The log records the original message, the fix, and the rule that triggered it.
Where does an enforcement runtime sit in the stack?
An enforcement runtime sits in the send path, after the model produces an output and before that output reaches a person, customer, or another system. An application can send the content to the runtime through an API and receive a verdict, or enforcement can happen at the surface where the AI communicates. The model itself does not need to change
What kinds of rules can an enforcement runtime apply?
An enforcement runtime can apply regulations, company policies, and security controls. ZeroDrift provides pre-built rulepacks for specific regulation areas, and companies can add their own policies and controls. The runtime enforces all of these rules on AI outputs before they are sent.