How Guardrails Helps You Protect Information

September 3, 2026

Organisations we work with increasingly have an AI policy. However, even if they do, many still are unsure whether anyone can actually follow it. That gap (between what the policy says, and what happens when someone pastes an email into ChatGPT at 4pm on a deadline) is why we built Guardrails.

Table of content

Let’s Make an Impact Together

We’re here to collaborate on projects that drive change.

  • Book a discovery meeting and share your digital challenge.
  • Speak to a UX expert for practical insights
  • Discuss partnerships to deliver effective digital solutions.
Book a discovery call

Save Your Seat Now

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Where Guardrails came from

At Yalla, we work with charities, non-profits and other social-impact organisations, and over the past couple of years we have run many sessions helping teams talk openly about AI. The same concern kept surfacing: people want to use AI to work faster, but they are also handling information that others have entrusted to them - supporter records, case notes, participant details - and they are not always sure where the line is.

Policies help, but only up to a point. They are often written in unfamiliar terminology, they live in a document nobody opens mid-task, and they rely on people noticing risky information at exactly the moment they are least likely to: when they are busy.

From these conversations. we realised there was a need to help with education while also offering practical ways to make the use of AI safer for organisations. This is how we came to build Guardrails.

We wanted to create a solution that helps keep data safer before it reaches AI and helps people build better habits around the safe use of AI.

What is Guardrails?

Guardrails is a Chrome extension that works alongside the AI chat tools you already use, such as ChatGPT, Gemini, Copilot and Claude. It is not a replacement for those tools. It sits in the flow between you and them.

It helps you:

  • Spot personal information in your prompts
  • See what information may identify someone
  • Mask, replace or remove personal information before it reaches the AI
  • Receive reminders about personal information in files you intend to use with AI
  • Access guidance provided by your organisation
  • Learn to recognise the information you may be sharing over time

Before your prompt is sent, Guardrails checks it for personally identifiable information, or PII. If something is detected, it shows you what it has found so you can review it before anything reaches the AI.

The basic process is:

You write -> Guardrails checks -> You review the suggestions -> You decide whether to apply them -> Your prompt continues to the AI

How Guardrails helps you catch what is easy to miss

Personal information can easily be included when we copy, paste or upload something while trying to get a task done.

You might paste an email and forget that the sender's name and email address are included. You might upload a report containing participant details. You might ask AI to summarise a complaint without noticing that a customer number or telephone number has been copied with it.

Guardrails flags these details before the prompt is sent.

For example, imagine you write:

"Please write a follow-up message to Daniel Roberts at daniel.roberts@example.com about the delayed project."

Guardrails can identify the name and email address so you can decide whether they need to be included.

Your prompt might become:

"Please write a follow-up message to [Person] about the delayed project."

When Guardrails identifies personal information, it does not automatically mean that the information is prohibited.

You decide what to do with each detection.

You might:

  • Replace it when the person's identity is not relevant to the task
  • Remove it when the information is not needed at all
  • Keep it when there is a legitimate reason for including it and your organisation permits that use

The purpose is to make the decision deliberate, and instead of sharing personal information simply because it happened to be included in what you copied or uploaded, you can ask:

Does the AI actually need this information?

Guardrails is a tool that hopes to make itself unnecessary

We think the best measure of Guardrails is not how much it catches, but how much you eventually catch yourself.

If it regularly flags names, email addresses, telephone numbers or other identifying details, you may start noticing the same information before submitting your prompt. You may begin removing unnecessary names before pasting text, sharing only the relevant part of a document, or noticing that an email address or identifier has nothing to do with the task. The habit moves from the tool to the person.

That is intentional. Guardrails is a safeguard, but it is also a way of building lasting awareness across a team - the kind that no policy document can create on its own.

How can I access Guardrails?

There are two main ways to use Guardrails: free individual access and organisation access.

Free individual access

Guardrails is free for individuals who want to spot and reduce personal information before sharing it with supported AI tools.

With individual access, you can:

  • Detect personal information in your prompts before it reaches the AI
  • Mask, replace or redact detected information
  • Review each detection and decide what to keep, change or remove
  • Receive reminders about personal information in attachments before sharing files with AI
  • Build awareness over time by learning to recognise personal information yourself

You can use Guardrails independently without being part of an organisation.

Organisation access

Organisations can provide Guardrails to their teams.

People in an organisation receive the same core protection as individual users. They can detect personal information, review it and decide what to redact, replace or keep.

Organisation access also includes additional tools for teams and administrators:

  • Organisation-wide insights: See anonymised and aggregated information about how often personal information is detected and addressed across the organisation. Administrators do not need access to individual prompts to see these patterns.
  • Organisation guidance and policies: Share the organisation's own AI guidance and policies so people can access them while using Guardrails.
  • Learning resources: Provide resources about personal information, data protection, AI use and other topics. Organisations can use the default Guardrails resources, edit them or add their own.
  • A shared prompt library: Create and share prompts that help teams write clearer and more effective instructions for AI instead of starting from scratch each time. This can also include resources developed with the ethical AI provider Thaura.

An individual can therefore use Guardrails for free, or they can be added to an organisation using Guardrails across its team.

In both cases, the person using AI remains in control of what they share.

Try it

  • Individuals: install the free Guardrails Chrome extension (will be available by September 20th ) and see what it catches in your next prompt.
  • Organisations: if you want to roll Guardrails out across your team, or talk through what safe AI use looks like for your organisation, get in touch with Lina at lina@yallacooperative.com

Let’s Make an Impact Together

We’re here to collaborate on projects that drive change.

Book a discovery meeting and share your digital challenge.Speak to a UX expert for practical insightsDiscuss partnerships to deliver effective digital solutions.

Book a discovery call

Save Your Seat Now

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.