From Alignment to Access Control: A Framework for GenAI Policy Enforcement
A framework maps generative AI policy enforcement from model alignment to access control.
Nathalie Baracaldo surveys policy enforcement for generative AI chat and agent applications, arguing that inconsistent meanings of policy produce siloed controls inadequate for compliance. The paper proposes a method to analyze existing enforcement approaches and issues recommendations for the community. It is a companion to the author's USENIX Security 2026 Enigma talk on a unified view from model alignment to access control. It notes that safety mechanisms have lagged rapid capability growth and that real incidents have already occurred.
- Frames GenAI policy from alignment through access control
- Argues inconsistent policy definitions create siloed controls
- Companion to a USENIX Security 2026 Enigma talk
- Recommends systematic analysis of enforcement approaches
Full article196 words · extracted from arxiv.org · click to collapse
Generative AI (GenAI) applications have flourished enabling users to chat with large language models, and to create agents to act on their behalf for a variety of tasks. The pace of development of capabilities in this field is incredibly fast with security and safety taking a back seat. Unfortunately, the slower pace at which security and safety mechanisms have evolved has led to real incidents. Policy enables the definition of desirable behavior of applications, and for that reason, it is a cornerstone of making systems secure and compliant. Policy however means different things to different practitioners creating confusion and siloed solutions that are not adequate for compliance. This paper takes a tour of the good, the bad and the ugly when it comes to policy enforcement in GenAI applications. We propose a methodology to systematically analyze and dissect existing approaches to define and enforce policy found in the wild. Based on this principled analysis, we provide recommendations and call for action for the community to address. This paper is a companion extension of USENIX Security 2026 Enigma talk titled "From Alignment to Access Control: A Unified View of GenAI Policy Enforcement" by the author Nathalie Baracaldo.
Text extracted automatically; images, tables and formatting may be missing. Original: https://arxiv.org/abs/2609.26682