Firewall for AI Configuration API

What it does

Firewall for AI Configuration API provides a self-service method for linking security configurations to AI firewall configurations to protect AI services hosted on the Akamai edge network from LLM-based threats.

Configuration

  • Provides policy-based configurations to apply actions when LLM rules are triggered.
  • Supports Alert and Deny actions for the LLM rules and Modify actions to replace an LLM-based app response with a custom safe response.
  • Integrates with Akamai WAF so that any existing WAF or DDoS rules are evaluated first, and only then the LLM-specific rules are applied.
  • Allows near-real-time updates to the detection rules (via FAI configuration) so that customers can adjust sensitivity and reduce false positives.
  • Enables linking a Security Configuration to one or more FAI configurations, specifying which application endpoints (URL match targets) are protected.

Threat detection and mitigation

  • Detects and mitigates LLM-specific threats such as prompt injections, jailbreaks, and data leaks.
  • Fails open if the detection service becomes unavailable or times out, allowing requests to the LLM-based app to continue rather than blocking traffic.
  • Uses rules to mitigate and categorize threats based on the OWASP Top-10 LLM Vulnerabilities list.

Reporting

You can analyze the events that triggered LLM rules by rule and by category. The event data is visible in Web Security Analytics (WSA) including:

  • the specific LLM rule triggered
  • the specific rule payload
  • the LLM prompt or response that triggered a rule. You can also opt-out of any logging of the payload fields' LLM prompt or response data.

Get started

Refer to the Firewall for AI Setup overview to begin.