Service policies for AI securables
Policies evaluated when a model is called and when it answers, returning allow, deny or ask, with built-in safety judges.
Why it is worth watching
The replacement for AI guardrails, and it fails closed by design.
What Beta promises
Open to most customers but not for production: support runs through engineering, and the shape of it can still move. On by default on Premium, off on Enterprise.
| Who can use it | Most customers |
|---|---|
| Production use | No |
| Support | Engineering only |
| On by default | Premium yes, Enterprise no |
The definitions are Databricks' own, on its release types page. The label on this page is the one the feature's documentation states, last checked on 14 Sept 2026.
Where to read more
We wrote it up: Guardrails for generative applications — Policies evaluated on the way in and on the way out of a model call, returning allow, deny or ask, plus the data-side masking that stops a prompt carrying what it should not. That page carries the Beta label while this entry does.
The Databricks documentation for Service policies for AI securables