Data Leakage & PII Protection
Preventing data leakage means detecting and redacting personal information before it reaches a prompt, a log, or a model’s output.
Overview
Personal data can leak from an AI system in more places than a typical application: in the prompt sent to a third-party provider, in logs captured for debugging, or in the model’s own generated output.
Where It Fits
User Input
PII Detection
Redaction
Prompt + Logs
Key Points
- Detection before transmission
- PII should be detected and redacted before it’s sent to a third-party model provider, not after.
- Logs are a leak surface too
- Logging full prompts and responses without redaction is a common, easy-to-overlook way sensitive data ends up stored indefinitely.
- Output-side leakage
- A model can also generate or repeat PII it saw earlier in a conversation or in retrieved context — output needs checking too, not just input.
Interview Question
Where in an AI pipeline can personal data leak, beyond the obvious risk of sending it to a model provider?
Logs are a major, easy-to-overlook one — capturing full prompts and responses for debugging without redaction stores sensitive data indefinitely. A model can also repeat PII it saw earlier in a conversation or in retrieved context in its own output, so output needs scanning too, not just the initial input.
Explain It in 30 Seconds
Preventing data leakage means scanning for and redacting PII before it reaches a prompt sent to a provider, before it’s written to logs, and checking model output too, since all three are places personal data can end up stored or exposed.
Real-World Stack
Technologies commonly used to implement this in production.