# Input and Output Checks — Safe Rollout Plans for AI Features

Source: https://www.skillbyai.com/en/ai-feature-rollouts/r-checks

> Filter before and after the model.

## Layers around the model

Wrap the model with checks: on **input**, validate size and format, redact personal data the model does not need, and detect obvious abuse or injection attempts; on **output**, validate format (for example JSON schema), check for personal data or secrets, run safety classifiers where appropriate, and verify claims against sources for retrieval features. Decide per check whether to block, repair, regenerate or fall back. Log check results; a spike in blocks is an early warning.

## Fail gracefully, spend safely

At runtime, fallbacks, circuit breakers and spend caps keep the product usable and budgets intact.

![Three ideas: input and output checks, fallbacks, spend caps.](assets/figures/ai-feature-rollouts/section-5-map.svg) — Figure 5.1 — Checks, fallbacks and spend caps.

## A request pipeline with checks

Checks on both sides of the model call.

```text
request
 -> input checks: length limit, PII redaction, abuse / injection heuristics
 -> retrieval (permission-filtered)
 -> model call (timeout, max tokens)
 -> output checks: schema valid? PII / secrets? safety classifier? cites sources?
    pass  -> show with "AI-generated" label + feedback buttons
    fail  -> regenerate once or fall back to the non-AI experience
 -> log: config version, check results, latency, tokens
```

## Prefer fallback over a bad answer

When an output fails checks twice, showing the non-AI experience is better than showing something questionable.

**Quiz:** What should happen when an output fails a schema or safety check?

- [ ] Retry forever
- [ ] Show it anyway
- [ ] Disable logging
- [x] Regenerate or fall back rather than show it

*Answer:* Regenerate or fall back rather than show it. Bounded retries, then fallback.
