Back to Gallery
Campaign Day 12#SpotTheLeak

SpotTheLeak Day 2

"Never paste Customer PII into any AI Prompts."

Vulnerability Focus

Scrub off any customer PII before you paste them to AI prompts.

This #SpotTheLeak episode tackles a habit that quietly creates compliance risk every day: pasting customer PII — names, emails, addresses, ID numbers — into AI prompts just to get the work done faster.

The compliance math

Customer PII is protected by privacy law and by the promises in your contracts. The moment it enters a third-party prompt it may be stored or reviewed outside your control, and a single paste can become a reportable incident.

Work fast without exposing people

  • Redact or tokenize personal fields before the prompt is sent.
  • Reference customers by an internal ID instead of their real details.
  • Choose tools that are contractually cleared to handle regulated data.

You can keep the speed of AI without gambling with people's data. Automatic PII redaction removes personal information from prompts on the way out, so productivity never comes at privacy's expense.

Share this insight