AI Automation

AI Workflows: Classify Fields Before Model Calls

AI Workflows: Classify Fields Before Model Calls

Classify the payload before the model call

Before any AI workflow calls a hosted large language model, classify each field in the request. Public text may leave the building. Internal records may leave only under enterprise terms that keep them out of training. Confidential fields need redaction or a private path. Regulated fields stay inside a controlled environment unless counsel has signed a documented exception. NIST's 2004 FIPS 199 still gives operations teams the test that matters: assign each information type an impact of low, moderate, or high for confidentiality, integrity, and availability, then treat the whole payload at the high-water mark of those values [1].

That decision is a data-handling rule, not a model-selection argument. It happens one step before the HTTP call, on the fields that would otherwise ride along in a prompt or a retrieved document.

Field labels, not system labels

Most organizations already have a system-level tag (the CRM is "confidential," the wiki is "internal"). AI workflows break that assumption. A single n8n node can pull a public product description, an internal ticket note, a confidential pricing worksheet, and a regulated identifier, then concatenate them into one prompt. The system tag no longer describes what actually leaves.

NIST Special Publication 800-60 Volume I Revision 1 (2008) maps information types (privacy, medical, proprietary, financial, contractor-sensitive, trade secret, investigative) onto consistent impact levels so agencies do not treat every record the same [2]. Operations teams can reuse that discipline without becoming a federal agency. Label the field. Inherit the strictest label in the payload. Refuse or redact before the model sees the string.

The 2024 NIST Generative AI Profile (NIST AI 600-1) is explicit about why the field, not the system, is the unit of risk. Generative systems can leak, generate, or infer biometric, health, location, or other personally identifiable information, including through memorization of training samples and through stitching facts that were never stored together [3]. Once a field is in the prompt, you are arguing about what a model may later emit, not about file-share permissions.

A joint May 2025 Cybersecurity Information Sheet from NSA, CISA, FBI, and partner agencies treats data used to train and operate AI systems as a supply-chain asset that must be protected from unauthorized discovery, access, use, modification, and destruction [4]. Prompt payloads are operating data. They sit in that supply chain whether or not you think of the workflow as "training."

Four operational classes

FIPS 199 does not use the words public, internal, confidential, and regulated. Those four labels are an operations overlay that our team uses so a workflow author can decide, in seconds, whether a field may travel. Map them back to confidentiality impact when you write the policy. Do not pretend they are a federal taxonomy.

Public. Information you would publish on a website, in a press release, or in a filed report. Product names, published prices, open job descriptions, and already-released financials. Confidentiality impact is not applicable or low. These fields may go to a hosted model on a standard API path.

Internal. Business records that are not secret, but are not for the street. Org charts, process notes, non-public meeting summaries, vendor names without contract terms. Unauthorized disclosure would be limited or, at most, serious. These fields may go to a hosted model only on a paid API path that contractually excludes training, and only after identifiers (personal email, employee ID) are stripped.

Confidential. Trade secrets, unreleased financials, customer lists, legal strategy, unpublished source, and anything whose disclosure would cause serious harm to operations, assets, or people. These fields do not go to a multi-tenant hosted model in raw form. Redact to a public or internal residue, or route the call to a self-hosted or VPC-isolated model that never leaves your tenancy.

Regulated. Data whose handling is dictated by statute or by a named regime: protected health information, payment card data, government identifiers, children's data, special-category personal data under UK GDPR, and any field a contract treats as personal data of a European or UK resident. These fields do not leave for a hosted model unless legal has a current data-processing agreement, a documented lawful basis, and a retention control that matches the regime. Default is refuse.

The UK Information Commissioner's Office states the fairness test in plain language: process personal data only in ways people would reasonably expect, and not in ways that have unjustified adverse effects [5]. Sending a customer's health note or a staff passport number into a general-purpose model is rarely within those expectations.

Handling rules by class

Write the rule as a table the workflow can enforce. Human review of every prompt does not scale. A field map does.

Public fields: allow the hosted path. Log the class and the destination. No redaction required.

Internal fields: allow the hosted path only if the destination is a paid or commercial API whose current terms exclude training on inputs and outputs. Strip direct identifiers. Prefer sending a role, a ticket category, or a hashed key rather than a name. The ICO's data-minimisation chapter is direct on this point: personal data must be adequate, relevant, and limited to what is necessary for the purpose, and AI does not create an exemption [6].

Confidential fields: default deny on the hosted path. Two allowed exits. First, redact until the residue is public or internal, then send the residue. Second, send the raw field only to a model that runs in your VPC, on your metal, or under a private endpoint with no training, no human review of prompts, and a retention clock you can prove. If neither exit is available, the node fails closed.

Regulated fields: default deny. A named exception (for example a HIPAA business associate agreement plus zero-data-retention on an eligible endpoint) is a legal artifact, not a toggle a developer flips. OECD's AI Principles, updated in May 2024, tell AI actors to respect privacy and data protection through the full system lifecycle and to keep traceability of datasets, processes, and decisions [7]. An unsigned comment in a workflow is not traceability.

Apply the high-water mark. If one field in a 12-field object is regulated, the object is regulated until that field is removed. FIPS 199's system rule is the same idea: the category of the system is the highest impact among the information types it holds [1]. Concatenation is not anonymization.

What vendors actually retain (and what they do not)

Vendor training promises are not a substitute for classification. They are an input to the internal and confidential rows of the table, and they change. Date them.

OpenAI's platform documentation states that, as of 1 March 2023, data sent to the OpenAI API is not used to train or improve OpenAI models unless the customer explicitly opts in [8]. The same page states that abuse-monitoring logs, which may contain prompts and responses, are retained by default for up to 30 days, and that zero-data-retention is an approved control, not the default [8]. "Not used for training" is not the same as "not stored."

Anthropic's commercial privacy article, covering Claude for Work, the Anthropic API, and Claude Gov, states that inputs and outputs from those products are not used to train models by default, and that feedback submitted through thumbs-up or thumbs-down may be stored for up to five years and used for training [9]. A workflow that silently forwards customer records, then lets an operator tap a feedback button, has just changed the retention clock.

Google's Gemini Developer API documentation, last updated 14 September 2026, states that Paid Services do not use prompts or responses to improve products, and that guaranteed zero-data-retention or enterprise processing agreements require Vertex AI (Gemini Enterprise Agent Platform), not the consumer-style developer API [10]. Grounding with Google Search stores prompts and generated output for 30 days with no off switch if that feature is used [10]. Feature flags are classification events.

None of those pages authorizes regulated data. They describe commercial defaults. Read the current terms for the exact product, region, and endpoint your workflow calls. If the workflow can fail over from a paid key to a free key, the classification rule has to fail with it.

How to log the decision

A policy that nobody can audit is a suggestion. OECD's accountability principle asks AI actors to keep traceability of datasets, processes, and decisions during the lifecycle so outputs can be analyzed and inquiries answered [7]. For a workflow, that means logging the classification, not only the prompt.

Minimum record, stored with the run, not in the model vendor's console: workflow and node IDs, policy version, timestamp, service account, destination (vendor, product, endpoint, region, paid vs. free, zero-retention flag), field classes and the high-water mark, redaction actions, the decision (allow hosted, allow private path, refuse), and any legal exception ID with expiry.

Do not log the raw confidential or regulated value in the same store as the decision unless that store already meets the class. Log the token, the hash, or the field name. The ICO treats unnecessary retention as unfair processing: keep data only as long as you need it for the purpose [5]. Decision logs can be internal. Prompt archives of health or payment fields cannot.

Review the log the way you would review an access-control change. Sample weekly. Alert on class upgrades, destination drift (a node that used a zero-retention project last week now posts to a default project), and silent concatenation of an unlabelled column.

Teams that operate across Charlotte, Raleigh, Asheville, and Philadelphia already move records across state lines. The class should travel with the field. The office that last edited the ticket does not get a weaker rule.

Practical takeaways

  • Classify at field level before any AI workflow calls an external model. System tags are not enough once an automation concatenates sources.
  • Use four operational classes (public, internal, confidential, regulated) mapped to confidentiality impact. Apply the high-water mark to the whole payload [1].
  • Public may use a hosted API. Internal may use a paid commercial API with a current no-training term, after identifiers are stripped [8][9][10].
  • Confidential stays on a private path or is redacted to a lower class. Regulated is refuse unless a named legal exception is in force [5][6].
  • Do not treat "we do not train on your data" as "we do not retain your data." OpenAI's default API abuse logs last up to 30 days; Anthropic feedback can last up to five years; Google Search grounding stores prompts for 30 days [8][9][10].
  • Log the class, destination, redaction, decision, and policy version with the run. Do not log the raw secret next to the decision [7].
  • Re-read vendor pages on a calendar. A workflow that was compliant in March can be out of policy in September with no code change.

This is not a data-cleanup project and it is not a perimeter project. Dirty records and weak networks are separate work. Classification is the gate that decides what a model is allowed to see.

Our team applies the same gate when we design production AI workflows: a field map, a destination allow-list, and a decision log a reviewer can read without reconstructing the prompt. The AI business tools we run internally follow the same rule. If a field cannot be classed, it does not travel.

How we can help

Have more questions or want to get in touch? We will walk your operations stack through a field-level classification, write the allow and refuse rules for each model destination, and stand up the decision log so the next workflow does not ship a regulated column by accident. Use our contact page, call (980) 322-4500, or email [email protected].

Citations

  1. NIST, "FIPS PUB 199: Standards for Security Categorization of Federal Information and Information Systems" (2004-02)
  2. NIST, "SP 800-60 Volume I Revision 1: Guide for Mapping Types of Information and Information Systems to Security Categories" (2008-08)
  3. NIST, "Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1)" (2024-07)
  4. NSA / CISA / FBI and partners, "AI Data Security: Best Practices for Securing Data Used to Train & Operate AI Systems" (2025-05)
  5. UK Information Commissioner's Office, "How do we ensure fairness in AI?" (2023-03-15)
  6. UK Information Commissioner's Office, "How should we assess security and data minimisation in AI?" (undated guidance, accessed 2026-09-15)
  7. OECD.AI, "OECD AI Principles overview" (updated 2024-05)
  8. OpenAI, "Data controls in the OpenAI platform" (policy dated 2023-03-01; page accessed 2026-09-15)
  9. Anthropic, "Is my data used for model training?" (commercial products article, accessed 2026-09-15)
  10. Google AI for Developers, "Zero data retention in the Gemini Developer API" (2026-09-14)
Our Strongest Offering

Forge Your Next Website

Forged Sites are custom-built, static-first websites with a full AI content engine on board — no CMS to log into, no plugins to break, no builder to fight.

  • Working target: WCAG 2.2 AA
  • During work hours, an account manager still reviews material changes
  • DraftDash auto-drafted blogs keep your content engine running
  • Ethel AI-powered forms filter spam and capture genuine leads