Responsible AI keeps sensitive data out of the system, so it cannot surface in an answer, summary, or generated document.
What it is
Responsible AI is a safeguard built into ingestion. Every file entering your workspace is checked for the sensitive information you define. Anything that matches is quarantined before it becomes searchable, so it never appears in an answer, a summary, or a generated document.
You define what counts as sensitive, and the check runs on every file as it is ingested.
What "quarantine" means: when a file is quarantined, it is set aside and hidden from search instead of being made available. It is not deleted. The file and its full record stay in the system so you can review it, and release it if it turns out to be safe. It is a holding area for anything that might contain protected data, kept out of reach until someone confirms it is fine.
Why use it
Protected content is caught during ingestion, before it becomes searchable.
You define what counts as sensitive, using your own SAP fields, secured lists, or protected data points rather than a generic template.
Every quarantine decision is logged with a reason, so you have evidence when compliance asks.
If a check cannot be completed, the file is held back rather than let through.
What it can do
Exclude files carrying your sensitivity labels (L1/L2) or DRM encryption from ever being ingested
Scan file contents for your defined sensitive fields across spreadsheets, documents, PDFs, text, code, and even text pulled from screenshots
Quarantine matches automatically and hides them from search
Withhold answers to questions that target restricted fields, returning a safe message instead
Give you a record of what was held back and why
Who it's for
Role | The day-to-day problem | How Responsible AI helps |
PMO | Sensitive data hides in migration files and test evidence, and you cannot manually police every upload. | Flags and quarantines protected content automatically, so program data stays clean without a review bottleneck. |
OCM | You have to reassure teams that AI will not leak protected information. | A clear, enforced guardrail you can point to when communicating what is protected and why. |
Exec / Compliance | You will be audited on responsible-AI commitments and need to prove controls exist. | Every decision is logged and explainable, ready as audit evidence. |
Delivery teams | You need answers fast but cannot risk surfacing restricted data. | The system withholds anything protected, so you can ask questions without exposing restricted data. |
Deep research and Ask Axia
Ask questions across your workspace and get answers drawn only from content that is cleared to be seen.
Quarantined files are not in the searchable set, so answers cannot be built from them.
If you ask directly for a protected field, the system returns a safe message ("we can't provide information on this field") instead of the value.
Answers are grounded in the documents that remain, with nothing protected included.
Document Generation
Every document you generate inherits the same protection. Because restricted content never enters the searchable set, it cannot be pulled into a draft, summary, or report.
How it works
Protection runs inline during ingestion, before a file is ever marked ready.
Label and encryption check. Files tagged with your sensitivity labels (L1/L2) or DRM-encrypted are excluded up front.
Keyword pre-filter. File content is scanned for the sensitive fields you have configured. No match, no further processing.
Content analysis. When a match is found, the file is analyzed in context to confirm whether real sensitive data is present. A field name in a header is treated differently from an actual value beneath it.
Decision. Sensitive files are quarantined and hidden from search. Clean files are released and searchable. If a scan cannot be completed, the file is quarantined by default, pending review.
Audit trail. The outcome, reason, and confidence are logged for every file.
Detection adapts to file type. Spreadsheets are checked column by value, documents for markings and data values, images via extracted text, and so on.
Tips for better questions
Be specific about the field or document you mean. Precise questions get precise, well-grounded answers.
If you hit a "can't provide" response, that is the guardrail working. The field is on your restricted list, not a system error.
Re-check classifications if a file you expected is missing. It may have been quarantined, and the audit log tells you why.
Frequently Asked Questions
Who decides what counts as sensitive?
Who decides what counts as sensitive?
You do. The system enforces the field list, labels, and secured data you configure. It does not guess on your behalf.
What happens to a quarantined file?
What happens to a quarantined file?
Its status changes to quarantined and it is hidden from search. The record stays intact for audit, and it can be reviewed or released through your workflow.
Does this slow ingestion down?
Does this slow ingestion down?
Slightly, and only for files that need a closer look, usually a few seconds each. Files with no keyword match skip the heavier analysis entirely.
What if the scan fails?
What if the scan fails?
The file is quarantined by default. Nothing sensitive is allowed through on a failed or incomplete check.
Can I get evidence for an audit?
Can I get evidence for an audit?
Yes. Every quarantine decision is logged with its reason and confidence, and can be reported back for compliance and privacy reviews.
Limitations worth knowing
Detection depends on the fields you define. If a protected data point is not on your configured list, the system does not know to look for it. Keeping the list current matters.
It reduces risk, but not to zero. Highly generic field names, unusual formats, or data buried in imperfectly extracted text (for example, poor-quality scans) can be harder to catch. Label-based exclusion is the most reliable control, and content scanning is a second layer beneath it.
Classification accuracy starts with your source labels. The system honors the sensitivity labels on your files. If a file was mislabeled at the source, the content scan is there to catch it, but correct labeling upstream is the most reliable protection.
A flagged file may need a human decision. Quarantine is designed to be cautious, so genuine business content can occasionally be held for review. That is the trade-off that keeps sensitive data out.