Search⌘ K
AI Features

Label What’s in the Prompt Before You Paste

Understand how to recognize and label various types of sensitive data within AI prompts, including PII, proprietary, operational, and Controlled Unclassified Information. Learn the importance of proper labeling, escalation protocols, and verifying authorized environments to maintain secure and compliant AI workflows in DoD and federal contexts.

The previous lesson left one pressure point hanging. People often cannot say what is in a draft prompt. Two incident summaries can look interchangeable. One reads like a public vulnerability note. The other reads like routine internal coordination. The difference is often one extra detail. The detail may be a name, unit label, system identifier, or other field that adds privacy, operational, or handling concerns to otherwise ordinary-looking text.

A drafter produced two paragraphs for a morning brief. Both described the same service disruption, the same mitigation, and the same status. One paragraph mentioned a vendor patch and a CVE (a public, cataloged vulnerability ID), and it stayed generic about affected users. The other included an analyst’s name, the on-call phone number, the affected site, and the internal ticket reference used for follow-up. Neither paragraph is labeled classified. In this scenario, the first contains only public, generic information, while the second contains additional details whose status and handling requirements must be considered before transfer.

Information categories are about access and rules

An information category describes the kind of information involved and helps identify which safeguarding, dissemination, privacy, contractual, or local-policy requirements may apply. A single prompt can contain several overlapping categories. A single prompt can contain more than one category because pasting work context tends to bundle things together. That bundling is where people get caught, since each added field changes who could be affected if it is exposed.

Some categories show up in almost every operational workflow, and they trigger consults rather than self-approval.

  • Personally Identifiable Information (PII) is information that can distinguish or trace an individual’s identity, either by itself or when combined with other information linked or linkable to that person. A name, phone number, unique role, or combination of fields may identify someone depending on context.

  • Proprietary or contractor information is non-public business information owned by a company. A product roadmap detail, a non-public vulnerability report, or pricing and licensing terms can land here.

  • Operational or mission-sensitive information is information that can create mission harm if exposed, even if not formally classified. Hostnames, internal IP ranges, unit locations, shift schedules, and incident response timing can all raise this concern in context.

Other labels you may need to use in the moment are broader and more cautious. Controlled Unclassified Information (CUI) is information the government creates or possesses, or that an entity creates or possesses for or on behalf of the government, that a law, regulation, or government-wide policy requires or permits an agency to safeguard or control when disseminated. CUI does not include classified information. Do not infer CUI status from sensitivity alone. When status is uncertain, verify the applicable category and authority through the CUI Registry and your organization’s CUI process. Classified information is a separate route entirely, so if classification is uncertain, stop work and consult Security rather than guessing.

See how one field changes the whole prompt

A draft prompt often looks like a single block of text, but it is really a bundle of fields. Once a prompt includes a person’s name plus a contact path, it stops being just a technical summary and becomes about an identifiable individual. Once it includes unit or site identifiers plus system details, it can become operationally sensitive even when it never uses a classified term.

Label prompt fields by sensitivity and escalation need

Public-facing brief

Service issue, vendor patch, CVE

Public

Low; general audience

Proceed with minimal detail

Internal working note

Analyst name, on-call phone

PII

Named analyst and coworkers

Remove identifiers; consult Privacy if they must stay

Contract-sensitive draft

Product name, non-public terms

Proprietary/contractor

Vendor and government buyer

Pause; consult Legal and Contracting

Mission-coordination note

Unit, site, internal ticket

Operational/mission-sensitive

Unit members and mission posture

Route to Security and CIO

Ambiguous marked draft

Claimed CUI, uncertain basis

CUI unknown

All holders and reviewers

Stop and verify with authority

Classified-risk draft

Possible classified details

Classified uncertain

Mission and national security

Stop; consult Security immediately

Do you find this helpful?

Escalation is routing, not a personal judgment call

When you spot PII in the draft, the right next move is to route the question to the Privacy Officer or SAOP named in the AI Use Intake Note. That route matters because privacy decisions depend on context, purpose, and authority, not on how careful the writer feels. A fast workaround is to remove the personal fields and continue drafting with role-based placeholders until the privacy review clarifies what can be shared.

When you spot proprietary or contractor information, pause and route it to Legal or the Office of General Counsel (OGC) and Contracting or Acquisition, using the consult authorities already captured in the intake note. The key question is ownership and permission, because a disclosure can create contractual harm even if the data is not government-controlled. A practical fallback is to rewrite using public-only product descriptions, then hold the non-public specifics for an authorized internal workflow.

When you spot operational or mission-sensitive details, route to the Security or CIO path and the ISSM or ISSO channel already listed. That escalation is about mission harm, not about proving a label like CUI on the spot. If classification might be in play, treat uncertainty itself as the trigger, stop transferring details, and consult Security rather than trying to sanitize your way into permission.

Practice the close calls that trigger different choices

Two summaries can share the same phrasing and still require different handling. A public-facing note stays at the level of a service name and generic mitigations. An internal-only note starts to include internal identifiers, staff names, or ticket references that connect to real people and systems. An escalated note adds operational context, like exact locations, schedules, or unique infrastructure details that could be exploited or that could expose mission posture.

Label What’s in the Prompt Before You Paste
Five short incident-summary snippets need routing before anyone pastes them into an AI tool. Decide whether each can proceed publicly, needs fields removed first, or must stop for consultation.
Now classifyingPatch note summaryMorning brief says a vendor released a patch for a common router flaw, with no site names, ticket numbers, or staff identifiers.
Item 1 of 5
Proceed
0 placed
The snippet contains only public, generic information with no identifiable people, proprietary detail, operationally sensitive specifics, or classified uncertainty.
Remove fields
0 placed
The snippet can be made safe to paste by removing or abstracting names, contact details, internal identifiers, or similar fields while keeping the general topic.
Stop/Consult
0 placed
The snippet includes PII the task actually needs, proprietary/contractor material, classified uncertainty, or operational/mission-sensitive details that require consulting the named authority before pasting.
Do you find this helpful?

Use a scale, and record uncertainty instead of guessing

Information handling is rarely captured by one label. A prompt can contain overlapping privacy, proprietary, operational, CUI, or other concerns, and combinations of fields can change what review or handling is needed. The safer habit is to label what you can, flag what you cannot, and keep the work moving using minimized or public-only inputs while the right authority answers the question.

If you cannot confidently label what it is and who owns it, do not paste it. Record the uncertainty as an unknown in your workflow notes, then consult the authorities already named in the AI Use Intake Note. CUI status is a common uncertainty, and it has a specific verification source. The next lesson uses the NARA CUI Registry to verify whether a claimed CUI category is real and applicable.