AI

RAG

Retrieval-Augmented Generation connects a language model with a knowledge source, basing its answers on retrieved documents.

Retrieval-Augmented Generation (RAG) connects a language model to a specific knowledge source. Before responding, the system searches for relevant documents, and the model bases its answer on this content.

How it works

Documents are broken down into small sections and stored as vectors in a database. When a question is asked, the system searches for the most relevant sections. These sections are passed to the language model along with the original question. The model then formulates an answer and can cite its sources. This allows the use of current and internal information without retraining the model.

A practical example

An analyst investigates an Alert on a server. The system searches previous Cases, Playbooks, and asset documentation for matching entries. It shows that the same Alert was triggered by a maintenance script three months ago. The analyst verifies this information and can close the Case more quickly.

What to look out for

  • The output quality depends on the sources. Outdated documents lead to incorrect answers.
  • Access rights must also apply within the RAG system to prevent unauthorised content exposure.
  • Answers should cite their sources so the information can be verified.
  • Documents may contain hidden instructions. Protect the system against prompt injection.
  • Measure the output quality using a fixed set of test questions.

Switzerland and regulation

If a RAG system processes personal data or confidential documents, the revFADP (revised Federal Act on Data Protection) applies. It is important to clarify where the model and database are operated. You must also determine if data is transferred abroad.

Typical mistakes

A frequent mistake is ingesting all available documents without selection. This worsens results and increases the risk of exposing confidential information. Another common error is a lack of maintenance. The knowledge base becomes outdated without anyone noticing it.

How we implement it

Our agents use RAG across Case history, Playbooks, and knowledge about your environment. Each customer is technically separated, and every assessment is filed with evidence in the Case.

How ANOMAL implements this