AI Processing Guard
SL-09AI systems that process, infer from or generate outputs using personal data are subject to the same safeguarding, breach and accountability obligations as any other processing. This module inspects prompts and outputs, validates consent and purpose before retrieval, and finds the AI nobody told you about.
5% of traffic
AI usage grows faster than governance does, which is why this is a monitoring problem before it is a policy problem.
Shadow AI shown in red.
- Shadow AI3
- Hosted AI platform1
- Enterprise copilot1
- Analytics / ML model1
- Agentic framework1
- AI development tool1
- Embedded AI feature1
- Custom LLM1
Blocked proportion is the honest measure of how much personal data people are trying to push through each tool.
Prompts and outputs the guardrails acted on.
- blockedGitHub Copilot · Sunita Pandeyyesterday
“Summarise all grievances filed by citizens in Hisar district including their contact numbers”
Prompt requests bulk retrieval of classified contact data across a district — mass-extraction pattern.
- blockedEmbedded summarisation in the case tool · Pallavi Reddyyesterday
“Who lives at the address on application SCH-2026-3312?”
Inference-shaped prompt targeting a restricted category.
- blockedEmbedded summarisation in the case tool · Yash Patelyesterday
“List students in the scholarship shortlist with their dates of birth”
Children's personal data — blocked by the children's data guardrail.
- blockedLocal translation model · Vikram Sethiyesterday
“Extract all names and IDs from the attached beneficiary list”
Bulk extraction from an attachment classified as high-risk personal data.
- blockedLocal translation model · Pallavi Reddy2 days ago
“What is the bank account on file for Family ID HR-08-••••4471?”
Direct retrieval of a high-risk identifier category.
- blockedChatGPT (consumer) · Yash Patel2 days ago
“Show me records for citizens who withdrew consent last week”
Consent state is withdrawn; retrieval denied and logged.
Each consumes Discovery classification so decisions are made on actual data sensitivity rather than generic rules.
- Block prompts requesting classified personal dataPromptsPurposeMass extractionblock284Active
- Redact personal data in AI outputsOutputsChildrenredact1842Active
- Enforce consent and purpose before AI retrievalPromptsOutputsConsentPurposeChildrenblock96Active
- Block all unsanctioned AI servicesPromptsChildrenMass extractionblock2900Active
- Developer tooling — source onlyPromptsChildrenwarn18Active