What it does
Firewall for AI Configuration API provides a self-service method for linking security configurations to AI firewall configurations to protect AI services hosted on the Akamai edge network from LLM-based threats.
Configuration
- Provides policy-based configurations to apply actions when LLM rules are triggered.
- Supports Alert and Deny actions for the LLM rules and Modify actions to replace an LLM-based app response with a custom safe response.
- Integrates with Akamai WAF so that any existing WAF or DDoS rules are evaluated first, and only then the LLM-specific rules are applied.
- Allows near-real-time updates to the detection rules (via FAI configuration) so that customers can adjust sensitivity and reduce false positives.
- Enables linking a Security Configuration to one or more FAI configurations, specifying which application endpoints (URL match targets) are protected.
Threat detection and mitigation
- Detects and mitigates LLM-specific threats such as prompt injections, jailbreaks, and data leaks.
- Fails open if the detection service becomes unavailable or times out, allowing requests to the LLM-based app to continue rather than blocking traffic.
- Uses rules to mitigate and categorize threats based on the OWASP Top-10 LLM Vulnerabilities list.
Reporting
You can analyze the events that triggered LLM rules by rule and by category. The event data is visible in Web Security Analytics (WSA) including:
- the specific LLM rule triggered
- the specific rule payload
- the LLM prompt or response that triggered a rule. You can also opt-out of any logging of the payload fields' LLM prompt or response data.
Get started
Refer to the Firewall for AI Setup overview to begin.
