We added a PII gate before the LLM call: SSNs get a 400 before ever reaching the model

Scholeristical · reddit · 2026-09-09

A privacy-engineering writeup: the product sends user-pasted text to an LLM, and a review asked the obvious question — what stops someone from pasting in an SSN? Nothing, until this week.

Key takeaway: much of "responsible AI" work is deciding what not to send upstream, screening hard before the call rather than constraining the model after the fact.

Original post →

More from coding & agent

coding & agent channel →