Control
GenAI output path without PII/sensitive-data leakage detection
GAI systems should detect the presence of PII or sensitive data in generated outputs to prevent memorization-driven leakage.
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.
Reach
The guard to add
Scan generated output for personal data, credentials, and secrets, and redact or block it before it is returned, posted, or sent beyond its authorized audience.
An output data-loss check in one shared helper that every outbound path uses: chat replies shown to users outside the data's scope, emails, Slack or webhook posts, tickets, and public pages. Run a PII and secret detector (Presidio AnalyzerEngine/AnonymizerEngine, llm_guard Sensitive, Azure AI Language PII, Google Cloud DLP) on the generated text, redact or block according to policy, and log the entity types found (not the values). Strip markdown images and links whose host is not on an allowlist, since an injected URL can carry data out.
Where it goes: 9 AI output handling, 6 API calls and integrations, 15 agent action surface.
What reviewers look for: no requests.post(, chat_postMessage(, send_email( or public render that takes completion text directly; each such sink receives the output of a redaction or DLP call (redact_pii(, presidio, llm_guard Sensitive, cloud DLP) and output links or images are filtered to allowlisted domains.
Example (Python + Presidio + Slack SDK), before:
summary = completion.choices[0].message.content
slack_client.chat_postMessage(channel=SUPPORT_CHANNEL, text=summary)After:
from presidio_analyzer import AnalyzerEngine
from presidio_anonymizer import AnonymizerEngine
analyzer, anonymizer = AnalyzerEngine(), AnonymizerEngine()
def redact_pii(text: str) -> str:
findings = analyzer.analyze(text=text, language='en')
return anonymizer.anonymize(text=text, analyzer_results=findings).text
summary = redact_pii(completion.choices[0].message.content)
slack_client.chat_postMessage(channel=SUPPORT_CHANNEL, text=summary)Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.
Every rule this guard addresses
Standard / soft law (1)
- Everywhere (*)
- GenAI outputs should be screened for PII/sensitive-data leakage (NIST GenAI Profile) NIST AI 600-1 §2.4 (Data Privacy) + MP-4.1-009
TwinEthos recommendation (not law) (1)
- Everywhere (*)
- Screen model and agent output for personal and sensitive data before it leaves the trust boundary TwinEthos derivation — guardrail.output-pii-leakage-screening
Related incidents
- Slack AI indirect prompt injection (researcher disclosure) (2024-08; confirmed). Researchers showed that an instruction planted in a public Slack channel could make Slack AI leak private-channel data through a crafted link. Salesforce patched the issue and reported no evidence of unauthorized access to customer data. Source: PromptArmor (original researcher disclosure) · evidence grade: primary · cited by Screen model and agent output for personal and sensitive data before it leaves the trust boundary