Overview
How might we design privacy filters so people can trust and act on AI output?
When to use
- Essential for enterprise applications, healthcare systems, and platforms handling sensitive data where automatic PII detection and masking protects user privacy.
When to skip
- Creative tools where users intentionally paste private drafts and need full fidelity.
- Admin audit views that are already access-controlled and must show raw values.
- Offline local models with no outbound risk and no compliance requirement to mask.
Rules
Silent dropping of PII with no indication anything was removed.
Masking that breaks copy/paste for roles that are allowed to see the value.
False confidence: labeling content safe when detection coverage is partial.
Blurring screenshots in marketing while leaving the same PII in exportable text.
Evidence
| Product | Implementation |
|---|---|
| Glean | Enterprise search controls that respect ACL and sensitive fields. |
| Healthcare AI tools | PHI masking in transcripts and generated notes. |
| Financial platforms | Account and card redaction in AI summaries and support views. |
| Enterprise chatbots | Prompt and response filters for emails, phones, and IDs. |