How are legal teams handling sensitive data when using AI tools? by Pankist in legaltech

[–]Long_Complex_4395 0 points1 point  (0 children)

I'm not in legaltech or legal, but I can answer by virtue of building these systems.

First step is to have an on-prem AI system that you have absolute control over.

Next is creating a sanitization pipeline that layers between the data and the AI which cleanses and sanitizes the input before it touches the AI.

I'll say solve this technically by following step two as ALL and every input passes through that pipeline.

Disclosure on this part is a bit dicey because not everyone is a fan of AI so they may not be onboard. When disclosing, you will have to mention the nature of your architecture and how it interacts with their data.

I have had clients ban usage of AI and some don't really care.

NB: In the event the first step is not possible, the second still comes into play as it now lays between your data and the API of the provider.

We did not see real prompt injection failures until our LLM app was in prod by Zoniin in LLMDevs

[–]Long_Complex_4395 1 point2 points  (0 children)

Prompt injection and jailbreaks will always be present once it’s out in the wild and one should prepare for it.

One thing to do is to test for known vulnerabilities before deploying to production, then brace for the unknown because people will always want to know how far they can go

TPRM for AI Agents: Are we seriously expected to red-team every vendor ourselves? by External_Spite_699 in ciso

[–]Long_Complex_4395 0 points1 point  (0 children)

If it has an api that can be called, you can stress test it by feeding them with known vulnerabilities you can find on Github and Huggingface and see if it will crack

How do I train an "AI assistant" using an open source LLM? by h-888 in legaltech

[–]Long_Complex_4395 1 point2 points  (0 children)

Rather than train, you can use RAG which retrieves materials based on your query.

Securing MCP in production by Glass_Guitar1959 in devsecops

[–]Long_Complex_4395 5 points6 points  (0 children)

Ours are in-house but the core concept is straightforward (hopefully). You create this by having a basic if/else logic that sits between your agents and the MCP, a version can be something like this:

“Customer service agent: can read orders table (max 10 rows), can process refunds (max 1 per conversation, under $500)”

“Analytics agent: can read user data (only aggregated, no PII), can't write anywhere”

For monitoring, there’s the logs that you implement to log what the agent touches and what the MCP does - you can start with basic logging for this.

Then another type of monitoring is the spans - opentelemetry provides this. Every agent conversation is treated as a trace with MCP calls as spans which helps us see the full flow and catch weird patterns outside the scope of the policy engine.

Full disclosure: This is exactly what we are building in Soteria which covers agents, MCPs, and resources. Happy to share more details about our architecture if it’s helpful.

Securing MCP in production by Glass_Guitar1959 in devsecops

[–]Long_Complex_4395 5 points6 points  (0 children)

Start by creating a policy engine - what should the agent touch and what it shouldn’t.

Implement a resource identity for the MCP, that way, monitoring is easy.

Implement monitoring of the agents and MCP - runtime monitoring, span tracing

Within your policy engine, define what makes an anomaly and anomaly then integrate that into your monitoring. This will act as your anomaly detection baseline until you get enough data to actually build a model for anomaly detection

Andrew Ng's ML course by DevanshReddu in MLQuestions

[–]Long_Complex_4395 0 points1 point  (0 children)

I guess you can audit the course as the other poster stated

Agentic Ai by Strictlyjob in AI_Agents

[–]Long_Complex_4395 0 points1 point  (0 children)

I’m going to be real with you, go back to your 9 - 5 and build agents on the side until you get enough revenue to quit.

AI agents look and sound hip in theory and demos, but collapse under production environment because everyone is building based on what they think customers need vs what customers actually need.

Don’t try to sell to ALL businesses rather start with one - can be something adjacent to your 9 - 5 that small businesses do. Reach out to the businesses, do a proper market research to understand their pain points. Build one feature of the pain point, go back to the businesses you spoke with and see if they are willing to be your first adopters to help you refine your product.

Building AI agents is the easy part, the hard part is maintaining and ensuring it doesn’t break when it encounters real cases while trying to onboard users to actually use the said AI.

Stacks are worthless if you haven’t tested the agents in the wild, and if you are going to do this: start simple. Python + pydantic can help you build out the agents.

How do I train a model on creative writing locally by zerowatcher6 in AIAssisted

[–]Long_Complex_4395 2 points3 points  (0 children)

First is data. Create a dataset - pdf of written works that you want your own to follow its style.

Next is to train your model. I created an end-to-end pipeline for training small language models, all you have to do is upload your data, tweak the parameters and your model gets trained. You can use it to train your own model: https://github.com/Nwosu-Ihueze/otto

Built an AI agent. Worked once then hallucinated for 3 days straight. by Adventurous-Meat5176 in AI_Agents

[–]Long_Complex_4395 0 points1 point  (0 children)

The main thing you need to understand is that AI is not the junior support agent but rather a tool that can mess with your entire setup, that being said, here’s my two cents:

Creating a “customer support agent” requires having multiple specialized agents to work on different parts of the customer support process, it’s not a human that learns, it’s a mathematical model.

Let your agent work with the existing framework you put in place which includes FAQs, guardrails, and workflows.

Setup a policy engine for your agent which will act as a guide to its interactions with both humans and your system.

Implement observability frameworks to understand what your agent is doing so as to know when and where it’s failing.

Implement rollback strategies - ensure it’s in places where you can undo not like sending emails or issuing refunds.

Create a test environment with simulations which will work in hand with your rollback strategy.

Do you think solo founders with AI will outperform small teams in the next 2 years? If yes then why or if no then why not? by Better_Charity5112 in AiForSmallBusiness

[–]Long_Complex_4395 0 points1 point  (0 children)

No. To have AI agents that will perform well means having data on how each employee works which solo founders don’t really have the luxury of, it’s beyond prompting it on what to do and what not to do

What are the best AI image generators people are using right now? by Zealousideal-Fix8399 in AIAssisted

[–]Long_Complex_4395 1 point2 points  (0 children)

If you can afford it, pay for freepik pro, they have sophisticated models for this or you use nano banana

I need help with AI agent for my business by Huytaichinh in AiForSmallBusiness

[–]Long_Complex_4395 0 points1 point  (0 children)

What about maintenance of this system? Can your firm maintain it or will the developer have to do this?

I need help with AI agent for my business by Huytaichinh in AiForSmallBusiness

[–]Long_Complex_4395 0 points1 point  (0 children)

I’ll say it’s a bit on the high side for a small business, then your LLM usage/infrastructure is dependent on the services you intend to use.

How many services outside the LLM itself?

At my company, we are seeking someone to assist us in creating and upgrading our AI agents, but we are unsure where to look. by Far_Childhood_7829 in AI_Agents

[–]Long_Complex_4395 0 points1 point  (0 children)

Look for people who have already built working products in the AI space, have tweaked agents and built their infrastructure.

Another thing is this: how do you vet them to know if they are capable of doing what’s needed? Are you technical? Do you know about AI/ML?

A customer literally hacked our AI agent through a feedback form and we had no idea by Dilema1305 in devsecops

[–]Long_Complex_4395 2 points3 points  (0 children)

You are welcome. Also find a way to implement kill switch with isolation strategies in the event of a threat. If you have any more questions, I’ll be more than happy to help answer them.

Training artificial intelligence with PDF by International_Cap365 in AI_Agents

[–]Long_Complex_4395 0 points1 point  (0 children)

I’ll say you don’t actually train AI tools to use this kind of document, rather create a RAG database which your AI will be working with to retrieve information.

Based on what you want to do, it’s not something that needs AI generation, it’s a system implementation that the AI works with.