The distinction that matters: an instruction is a request and a guardrail is a constraint. "Do not spend more than fifty pounds" in a prompt is a hope. A credit ceiling that halts the run is a guardrail.
They belong at the points where a plausible wrong answer is expensive: spend, access, publication, deletion. Everywhere else, an instruction is fine and a guardrail is friction.
The test is simple. If a confused or adversarial run could ignore it, it is an instruction. If it physically cannot, it is a guardrail.
What is the difference between a guardrail and an instruction?
An instruction is a request the model can fail to follow. A guardrail is enforced outside the model, so a confused or adversarial run cannot get past it.
Where are guardrails actually needed?
Spend, access, publication and deletion. Elsewhere they are friction, and friction gets routed around.
