Atlas · skill

AI Data Security

AI data security protects the confidentiality and integrity of information as it moves through datasets, model services, retrieval systems and agents. The skill focuses on preventing unauthorized access, disclosure or modification, including exposures introduced by prompts, generated outputs, tool calls and operational logs.

conceptAI Security

What it is

AI applications often move the same information through several representations and services. A record may appear in a training file, an embedding index, a prompt trace and an answer cache, each with different access controls and retention behavior. Data security treats these as parts of one information flow rather than assuming the model endpoint is the only boundary. Confidentiality concerns who can learn the information; integrity concerns whether it can be altered without authorization. Privacy adds questions about people and permitted processing, while security also covers credentials, commercial secrets and other protected assets.

What the work involves

The practitioner inventories sensitive data and traces its paths through preprocessing, inference, retrieval and monitoring. They configure least-privilege identities, protect secrets outside prompts, restrict outbound destinations and decide which fields should be removed before external processing. A data-flow review should produce an access matrix, retention settings and tests for disclosure through errors, logs and tool responses. When a model provider is involved, the team verifies the actual service configuration and contractual data handling rather than inferring them from the word enterprise.

Illustrative example

A support assistant summarizes customer tickets using an external model. The engineer discovers that full ticket bodies also enter debug traces and a shared analytics store. They remove unnecessary identifiers before inference, restrict trace access and disable content logging where it is not needed. A seeded test ticket contains a fictitious secret, allowing the team to check every downstream store and outbound request without exposing real customer information during the review.

Limits and common mistakes

Redaction detectors miss unusual identifiers, and encryption does not help when an authorized application sends decrypted secrets to the wrong destination. Access policies must cover derived data and backups as well as originals. Security reviews should distinguish prevented disclosure from merely undetected disclosure, and verify negative paths. A clean sample of model answers does not prove that training membership, cached context or agent tools cannot reveal protected information.

Prerequisites

  • Data exfiltration defense includes securing RAG retrieval — secure RAG is one component of the broader defense

  • Data exfiltration often exploits prompt injection to bypass access controls

Related skills

Sources and further reading

Last updated: 2026-10-10