# Why Is Microsoft Foundry’s Content Filter Blocking Legitimate Medical Questions?

> Source: <https://www.machinebrief.com/news/why-is-microsoft-foundrys-content-filter-blocking-legitimate-8jmu>
> Published: 2026-10-06 07:30:53+00:00

Last Updated on October 6, 2026 by Editorial Team Author(s): Dave R | Microsoft Azure & AI MVP ☁️ Originally published on Towards AI. An AB-100 case study: read the guardrail annotation, find the category and severity, and relax one threshold while Self-harm stays strict. An oncologist asks a clinical notes assistant built on Microsoft Foundry to summarize the risks of a high-dose chemotherapy plan, and the app gets back an HTTP 400 with the error code content_filter. The same assistant still declines off-topic questions exactly as intended. This scenario is the false positive that teams running AI in medicine, law, or security eventually meet. Here's how to find the exact category and severity behind the block, and how to fix it with a custom guardrail while Self-harm stays at the strictest setting. Why Is Microsoft Foundry’s Content Filter Blocking Legitimate Medical QuestionsThe article walks through a four-step approach to fix a medical-system false positive in Microsoft Foundry: first, diagnose by reading guardrail annotations returned with API calls (including distinguishing input-block vs completion-block vs model refusal), then identify the specific harm category, severity, and whether the block occurred on the prompt or the completion; next, create a custom guardrail (since the default one is read-only) by adjusting only the implicated threshold on only the side that was blocked—while keeping Self-harm at the strictest setting for clinical safety and governance—along with maintaining other controls; finally, prove the fix by rerunning both your clinical test set and an approved self-harm test set, checking Azure Monitor metrics for the expected “harmful detected stays, blocked volume drops” signature, and auditing changes via the Activity log. It also explains why common distractors fail (blocklists only add blocks, the Asynchronous Filter changes timing rather than behavior, and Activity log is for control-plane auditing not content diagnosis), and emphasizes operational cautions like not using relaxed Self-harm thresholds for real clinical contexts without compliance review and avoiding privacy leaks when logging annotations. Read the full blog for free on Medium. Join thousands of data leaders on the AI newsletter. Join over 80,000 subscribers and keep up to date with the latest developments in AI. From research to projects and ideas. If you are building an AI startup, an AI-related product, or a service, we invite you to consider becoming a sponsor. Published via Towards AI
