AI Shield — Project Story
Inspiration
As AI agents become more autonomous, they can perform actions much faster than humans can review them. We were inspired by a simple question: What happens when an AI agent is allowed to perform a sensitive action without a security checkpoint?
We identified three major gaps: access control, transparency, and human oversight. An AI agent might have the technical permission to perform an action, but that does not always mean the action should be executed.
This led us to build AI Shield, a real-time governance layer between autonomous AI agents and enterprise resources.
What We Built
AI Shield intercepts an agent's action request before execution.
The workflow is:
AI Agent
↓
Action Monitor
↓
Risk Classification
↓
Policy Engine
↓
Execution Gate
↓
┌──────────┬──────────────────┬─────────┐
│ ALLOW │ SEEK APPROVAL │ BLOCK │
└──────────┴──────────────────┴─────────┘
↓ ↓ ↓
Execute Human Review Reject
↓ ↓ ↓
Audit Log
Every action is evaluated and recorded, creating visibility into what an agent attempted, why it was considered risky, and what decision was made.
For high-impact actions, AI Shield introduces a human-in-the-loop approval process instead of allowing the agent to proceed automatically.
How We Built It
We used React.js for the interactive dashboard and real-time monitoring interface, Python with FastAPI for the governance backend, and MongoDB for storing action and audit information. REST APIs connect the components, with WebSockets supporting real-time updates.
Our architecture separates two important responsibilities:
- Risk evaluation — determines how risky an action is.
- Policy enforcement — determines whether that action should be allowed, sent for human approval, or blocked.
We also designed the system to support multiple AI agents through one centralized governance layer rather than implementing separate security controls inside every agent.
What We Learned
Building AI Shield helped us understand that AI security is not only about detecting malicious input. Controlling what an AI system is allowed to do is equally important.
We learned how to:
- Design a real-time AI governance architecture.
- Connect a React frontend with a FastAPI backend.
- Implement policy-based decision making.
- Design human approval workflows.
- Store and track actions through MongoDB.
- Think about explainability and auditability in AI systems.
- Design fallback mechanisms when ML-based evaluation could introduce latency.
One important lesson was that security decisions need to be explainable. Instead of simply saying “Blocked,” the system should provide the context behind the decision.
Challenges We Faced
One of our main challenges was designing a system that could evaluate actions without becoming a bottleneck. Machine-learning-based risk classification can introduce latency, which is problematic when agents need near-real-time responses.
To address this, our design includes a fast, pre-configured rule-based fallback for situations where ML evaluation could delay the decision.
Another challenge was designing the human-in-the-loop workflow. A high-risk action should not simply fail silently. Instead, it should be placed into an approval queue where an authorized administrator can review and approve or block it.
We also had to think carefully about the difference between governance and execution. AI Shield is designed to govern agent actions rather than replace the underlying AI agent or train a foundation model.
What's Next
Our longer-term vision is to extend AI Shield with natural-language security policy creation, stronger tamper-evident audit mechanisms, and adaptive policies that respond to changing agent behavior.
Ultimately, our goal is simple:
AI should be able to act autonomously, but its actions should remain visible, controlled, and accountable.
**AI Shield does not stop AI from acting. It creates the security checkpoint that makes AI accountable
Built With
- access-control
- ai-governance
- ai-security
- audit-logging
- autonomous-ai-agents
- cybersecurity
- docker
- explainable-ai
- fastapi
- human-in-the-loop
- machine-learning
- mongodb
- policy-engine
- python
- react.js
- real-time-monitoring
- rest-api
- risk-analysis
- websockets
Log in or sign up for Devpost to join the conversation.