Agentic guardrails should be deterministic and algorithmic as opposed to using LLM or relying on LLMs.

The moment you rely on LLM to be a guardrail, well you are risking it to fail.