Skip to main content
Every AI system is a pipeline. Data flows in, models reason over it, agents act on it, and responses reach your users. Each handoff in that pipeline is a potential entry point for attackers. The AI value chain is a mental model that names every node in that pipeline so you can reason about your attack surface systematically — and close the gaps before adversaries find them.

The Six Nodes

Your AI stack has six distinct layers, each with its own threat profile. Understanding what lives at each layer is the first step toward protecting it. Each layer compounds the ones beneath it. A poisoned RAG corpus (Data layer) can corrupt model responses (Model layer), which then drive an agent to take harmful actions (Agent layer), ultimately exposing sensitive data to an end user (User layer). A threat that enters at one node can propagate upward through every layer above it.

Why Traditional Controls Miss the AI Value Chain

Firewalls, DLP solutions, and CASB platforms were built for a different era. They inspect packets, match signatures, and enforce perimeter rules. What they cannot do is understand what an AI model is being asked to do, whether an agent’s plan is consistent with its authorized scope, or whether a retrieved document has been tampered with to manipulate downstream reasoning. Traditional tools see traffic. AI threats live inside the meaning of that traffic. A prompt injection attack looks like a normal user message to a firewall. A poisoned RAG document looks like legitimate knowledge base content to a DLP scanner. Shadow AI tools running inside your organization look like ordinary SaaS traffic to a CASB. None of these controls can interpret intent, evaluate context, or follow an agent’s reasoning chain — so they cannot detect the threats that matter most in an AI deployment.

Coverage with BeyondGuard

BeyondGuard deploys specialized Guards across the AI value chain. Rather than retrofitting general-purpose security tools to an AI context, each Guard is purpose-built for the layer it protects. RAG Guard and File Guard secure the data layer — retrieval sources, embeddings, and uploaded files. Prompt Guard inspects and filters inputs before they reach the model, and masks sensitive data on the way out. Context Guard governs the application layer, treating every response as untrusted output. Agent Guard tracks plan execution and memory integrity, and MCP Guard validates every tool and function call. All six Guards report into a single unified control plane, giving you end-to-end visibility and enforcement across the entire chain.
Learn how each Guard works, how they operate independently from the models they protect, and how to combine them for full-stack coverage in The Six Guards. For the individual checks behind each Guard, see the Controls Catalog.