User experience
When prompts are blocked
When the browser collector blocks a user prompt, the user sees a banner that includes:
- Message indicating that the prompt was blocked
- Request ID that users can copy and provide to Support
For example:
Malicious Prompt was detected and blocked.
Request ID: prq_b6m7di4yao3lc4q75j5lddx5y7licu5v ⧉
When data is transformed
When the browser collector transforms data, the AI provider receives redacted sensitive values and defanged malicious URLs, IP addresses, and domains. Some sites might show the original user input in the chat history.
Users see a banner message that includes:
- Message indicating that sensitive data was redacted or malicious references were defanged
- Request ID that users can copy and provide to Support
For example:
Your organization's security policy modified sensitive or malicious content before sending it to the AI provider.
Request ID: prq_b6m7di4yao3lc4q75j5lddx5y7licu5v ⧉
Users see transformed values in AI responses when the model repeats those values in its output.
Custom messages
By default, the banner displays a standard message in a popup. You can replace this with a custom message to provide context relevant to your organization. For example, include a link to an internal acceptable-use policy or instructions for requesting an exception. You can also disable the popup.
To configure custom block and transform messages, see the following documentation:
- Access Rules - Custom block messages
- Prompt Rules - Custom block messages
- Prompt Rules - Custom defang messages
- Prompt Rules - Custom redact messages
Inconsistent behavior across AI provider sites
AI provider sites handle AIDR security interventions differently based on their client-side web processing. These implementations can change at any time, are outside AIDR's control, and might result in inconsistent user experiences across platforms.