TL;DR: AI data classification inspects prompts, uploads, responses, retrieved context, and agent tool calls in flight so organisations can stop sensitive information reaching external models, according to WitnessAI. That matters because effective AI governance now depends on context-aware controls, audit evidence, and enforceable policies rather than keyword filters that miss meaning and generate noise.
NHIMG editorial — based on content published by WitnessAI: AI data classification and runtime AI governance
By the numbers:
- DLP accuracy research for unstructured content ranges from 5 to 25%, with false positive rates above 40%.
- A hybrid NLP and machine learning approach reached 94.7% precision on real-world financial documents.
- 17% of organisations have deployed AI agents, and 60% expect to within two years.
Questions worth separating out
Q: How should security teams govern AI prompts that include sensitive data?
A: Treat the browser as a control point, not just an interface.
Q: Why do keyword and regex controls fail for AI data protection?
A: They were built for fixed text patterns, while AI reshapes content continuously.
Q: What should teams do first when they cannot see AI data flows clearly?
A: Start with an AI system and tool inventory, then document which data types enter and leave each system.
Practitioner guidance
- Map AI interaction surfaces Inventory prompts, uploads, responses, retrieved context, and agent tool calls across sanctioned AI services so governance covers the full runtime path, not only browser use.
- Test classification against real traffic Measure precision and recall by data category using live prompts and outputs, then tune thresholds before introducing hard enforcement.
- Tie classifications to proportionate policy Use allow, warn, block, route, and tokenize actions so sensitive interactions are governed without forcing users into personal accounts or shadow tools.
What's in the full article
WitnessAI's full article covers the operational detail this post intentionally leaves for the source:
- Specific examples of how its classification engine handles prompts, uploads, responses, retrieved context, and tool calls
- The practical difference between allow, warn, block, route, and tokenise actions in live AI workflows
- How the platform attributes agent activity to a human identity and extends controls to MCP connections
- The model's runtime guardrail and output inspection approach across sanctioned AI traffic
👉 Read WitnessAI's analysis of AI data classification and runtime AI governance →
AI data classification and AI governance: are your controls keeping up?
Explore further
AI data classification is becoming the missing control layer between human intent and model exposure. File labels alone do not address prompts, responses, or agent tool calls, which is where sensitive data now crosses trust boundaries. The governance problem is not discovery after the fact but control before the model sees the content. Practitioners should treat runtime classification as a prerequisite for credible AI governance.
A question worth separating out:
Q: How do AI agents and MCP connections change governance requirements?
A: They extend classification from user content to delegated action. Agents can call tools at machine speed under inherited access, so teams need identity attribution, tool allow-lists, pre-execution checks, and audit trails. Without those controls, an agent can move sensitive data or trigger actions outside the intent of the human who launched it.
👉 Read our full editorial: AI data classification is closing the governance gap in model use