Giskard

Type: company (AI assurance / LLM security pure-play) Sector: AI testing, red-teaming, evaluation and guardrails First seen: 2026-07-08 (named as an adjacent evaluation player in [S-2026-06-18-pramaana-labs-seed]) Last updated: 2026-07-27

Created 2026-07-27 from S-2026-07-23-giskard-hf-breach-guards (daily AI-governance vendor-intelligence scan). Trigger: second source — previously referenced among adjacent evaluation/monitoring players in the Pramaana Labs capture.

Snapshot

Giskard is a French (“Built in Europe 🇫🇷”) AI-assurance vendor on Paul’s watchlist covering LLM testing, continuous red-teaming, evaluation and — since May 2026 — runtime guardrails (Giskard Guards). It matters to the wiki as one of the few EU-based players in the guardrail/red-teaming cohort, explicitly marketing EU sovereignty and on-premise deployment to regulated enterprises, and as the vendor whose incident analysis brought the July 2026 OpenAI/Hugging Face agent breach into the vault [S-2026-07-23-giskard-hf-breach-guards].

Positions / Claims they advance

  • Published (23 Jul 2026) a technical analysis of the OpenAI agent breach of Hugging Face, advancing a “guardrail asymmetry” thesis: provider-default safety filters blocked Hugging Face’s own forensic analysis while the attacking agent had run with guardrails removed — “the defenders bound by a usage policy that the attacker had never been subject to” [S-2026-07-23-giskard-hf-breach-guards]. Vendor editorial framing, though the underlying forensics-blocking episode is consistent with independent coverage surfaced in search.
  • Prescribes one guardrail policy per AI system — policy-as-code pairing detectors with per-label actions (allow / monitor / block, each decision returning an auditable event ID), differentiated by system risk profile (SOC assistant vs customer chatbot) [S-2026-07-23-giskard-hf-breach-guards]. Vendor capability claims, not independently verified.
  • Markets Guards (launched May 2026 per the same site) as “the first independent, EU-sovereign guardrail platform”, on-premise, with “ready-to-use EU AI Act and OWASP Top 10 LLM compliance packs” ⚠️ — a vendor assertion of regulatory alignment, not a conformity assessment; treat “EU AI Act compliance pack” with the standing scepticism for such claims [S-2026-07-23-giskard-hf-breach-guards].
  • Product line also spans continuous red-teaming, LLM evaluation, and published research (Phare LLM benchmark, RealHarm/RealPerformance databases, StereoTales) with sector pages for finance and healthcare LLM security [S-2026-07-23-giskard-hf-breach-guards] (site navigation; not independently assessed).

Relationships

  • relates-to → AI Governance Platforms — supplies the guardrail/runtime-policy locus of the layered agentic-governance architecture tracked there [S-2026-07-23-giskard-hf-breach-guards].
  • relates-to → Model Risk Management and Agentic AI — its incident analysis is the vault’s source for the strongest real-world instance of the “where the framework strains” thesis [S-2026-07-23-giskard-hf-breach-guards].
  • relates-to → EU AI Act — positions Guards’ compliance packs and EU sovereignty against the Act ⚠️ vendor-asserted [S-2026-07-23-giskard-hf-breach-guards].
  • competes-with → Patronus AI — adjacent AI-assurance/evaluation players; both named in the Pramaana adjacency list [S-2026-06-18-pramaana-labs-seed]. [inference]
  • competes-with → HiddenLayer — overlapping runtime AI-security/guardrail positioning for regulated buyers [inference].

Tracked changes

  • 2026-07-23 — Published OpenAI/Hugging Face breach analysis; positioned Guards as the customisable, auditable alternative to provider-default guardrails [S-2026-07-23-giskard-hf-breach-guards].
  • 2026-05 (per same-site blurb, not separately ingested) — Launched Guards, “EU-sovereign guardrail platform” with EU AI Act / OWASP policy packs ⚠️ [S-2026-07-23-giskard-hf-breach-guards].

Open Questions

  • No named regulated-FS reference customer captured — consistent with the category-wide gap tracked on AI Governance Platforms.
  • What the “EU AI Act compliance pack” concretely contains and whether it has been independently assessed.
  • Funding/scale profile not yet ingested from a primary source.

Sources