Stop rogue AI: Enforce policy & cut costs in Agent Development Kit (ADK)

Google Cloud TechAbout 3 min readMay 29, 2026Watch original
THE SUMMARYAI-generated

Key Concepts

  • Agent Callbacks: Middleware functions that intercept agent interactions to enforce business logic, safety, and performance optimizations.
  • Guardrails: Specific constraints placed on an AI agent to prevent it from straying from its intended purpose (e.g., avoiding financial advice).
  • Middleware Pattern: A software architecture that allows code execution at specific lifecycle stages (before/after agent, model, or tool calls).
  • Model Armor: A security tool for redacting sensitive data and preventing prompt injection, distinct from intent-based guardrails.
  • State Management: Using flags within a conversation context to track user interactions (e.g., ensuring a disclaimer is only shown once).

1. The Problem: AI "Hallucinations" and Scope Creep

AI chatbots often suffer from "scope creep," where they provide information outside their intended domain—such as a food delivery bot offering coding help or a financial bot providing unauthorized investment advice. This poses significant risks to brand reputation, legal compliance, and user safety.

2. The Solution: Agent Callbacks

Miguel, a Google Cloud expert, demonstrates how to use Agent Callbacks to act as "safety rails." These callbacks function as middleware, allowing developers to inject custom logic at critical points in the agent's lifecycle:

  • Before/After Agent calls
  • Before/After Model calls
  • Before/After Tool calls

3. Implementation Framework

The "Pro Advisor" financial chatbot example illustrates three primary use cases for callbacks:

A. Enforcing Disclaimers (State Management)

Instead of hardcoding a disclaimer into the system prompt (which might cause the bot to repeat it redundantly), a callback checks a flag in the conversation state.

  • Process: The function checks if disclaimer_shown is true. If not, it sets the flag to true and returns the disclaimer to the user. This ensures a "one-and-done" user experience.

B. Intent-Based Guardrails

To prevent the bot from acting as a financial advisor, the system uses a "judge" pattern.

  • Methodology: A smaller, faster, and more cost-effective model is used to analyze the user's intent. If the intent is identified as a request for financial advice, the callback returns a "blocked" message before the main agent ever processes the request.

C. Performance and Cost Optimization (Caching)

Callbacks are used to intercept common queries to save on token costs and latency.

  • Process: The cache_google_analysis function checks if the user's query matches a cached topic (e.g., "Google"). If a match is found, the system returns the cached response immediately, bypassing the LLM entirely.

4. Comparison: Callbacks vs. Other Tools

  • Callbacks vs. Model Armor: While Model Armor is essential for redacting PII (Personally Identifiable Information) and preventing prompt injection, it lacks the ability to understand complex user intent. Callbacks are required for logic-based guardrails that distinguish between "stock analysis" (allowed) and "stock recommendation" (blocked).
  • Callbacks vs. System Prompts: Hardcoding rules into system prompts is unreliable because the model may ignore them or repeat them excessively. Callbacks provide programmatic, deterministic control.

5. Key Takeaways

  1. Custom Guardrails: Use callbacks as a safety net to enforce specific business rules that generic filters cannot handle.
  2. Cost Efficiency: Implement caching via callbacks to avoid redundant token usage, which improves both speed and operational costs.

"Callbacks are like the safety rails on a balcony. They won't stop you from enjoying the view, but they will keep you from falling over the edge." — Miguel, Google Cloud

AI summaries can miss context or contain errors. Check important details against the original video.

Go a little deeper.

Have a question about this video? Load its transcript to open the video chat.