The AI Guardrails Add-on for Splunk normalizes AI guardrail and content-safety events from seven different providers into a unified schema mapped to the CIM Intrusion Detection data model. The add-on processes telemetry from AWS Bedrock Guardrails, Azure AI Content Safety, Azure OpenAI content filters, Google Vertex AI safety ratings, and self-hosted systems including Llama Guard, Lakera Guard, and NeMo Guardrails. Each guardrail system emits structured event data when policies fire, including the attempted action, triggered policy, category, severity, associated identity, and timestamp. By normalizing this data into a single CIM-compliant format, the add-on enables security operations teams to correlate AI guardrail violations with existing identity, DLP, and insider-threat detection content in Splunk Enterprise Security. The add-on assigns seven distinct sourcetypes corresponding to each provider and extracts events into fields that support detection, alerting, and investigation workflows.