Control #

C

3

.

1

Redact unnecessary PII from AI inputs automatically

Use automated systems to detect and remove unnecessary PII from user inputs before they reach the model. Redaction should occur in real time and cover direct and indirect identifiers. Necessary PII is allowed but should be justified.

Evidence

Screenshot of data masking logs prove that PII redaction is active and working

Recommended actions

We'll recommend specific practices and actions for complying with this control.

Provide feedback on this control