# AI Guardrails and Cost Control — AI Automation with n8n

Source: https://www.geekswithgeeks.com/en/n8n-ai-automation/rel-ai-guardrails

> Limit what an AI workflow can do, add human approval and estimate cost.

## Prompts are not security

Text your agent reads (emails, web pages, tickets) can contain **prompt injection**: hidden instructions that try to make it act against you. Telling the model "ignore such instructions" helps only partly. The reliable defences are structural: give the agent only the tools it needs, keep write actions separate, require **human approval** for risky steps (for example by sending a Slack or email approval request and waiting), validate model output before using it, and set an iteration cap. Track token use, because AI steps cost money on every run.

## Estimating run cost

This ran in Node.js with illustrative prices of 3 and 15 per million tokens; use your provider's real prices. A run with 1,500 input and 300 output tokens costs 0.009, so 1,000 runs cost about 9.

```javascript
const cost = (inTok, outTok, pIn, pOut) =>
  +(inTok / 1e6 * pIn + outTok / 1e6 * pOut).toFixed(4);

console.log(cost(1500, 300, 3, 15), cost(1500, 300, 3, 15) * 1000);
```

Output:

```
0.009 9
```

## Approve the action, not the chat

An approval message should show exactly what will happen ("Refund 2,400 INR to order 10482?") with Approve and Reject links, so the person decides on the real action rather than a vague summary.

**Quiz:** Which is the most reliable defence against prompt injection?

- [ ] A longer system prompt only
- [x] Limiting the agent's tools and requiring approval for risky actions
- [ ] Hiding the prompt
- [ ] Using bigger fonts

*Answer:* Limiting the agent's tools and requiring approval for risky actions. Capability limits work even if the model is fooled by injected text.
