Virginia county pilots AI data governance with redaction-at-use and data rehydration
route-fifty.com

Virginia county pilots AI data governance with redaction-at-use and data rehydration

Tech News
3 min read

Published by AINave Editorial • Reviewed by Ramit

TL;DRPrince William County, Virginia deployed Liminal to redact sensitive data at the point of use before sending prompts to AI platforms, then rehydrate responses with the original data. The pilot expanded from 150 users to 20 departments.

Prince William County, Virginia has adopted the Liminal AI platform to govern generative AI use by staff, using a redact-at-use and data rehydration approach that keeps sensitive data out of AI prompts while preserving context in final answers. The model offers a practical blueprint for any organization that needs to deploy AI in regulated environments.

How the redaction and rehydration flow works

When a county employee submits a prompt, Liminal identifies and redacts or masks personally identifiable information (PII) before the prompt reaches any generative AI platform. After the AI returns a response, the system reinserts the redacted data into the final answer. Dr. Alicia Hart, deputy county executive for government operations, performance and innovation, explained that this method ensures the intent and context of the prompt remain while staying compliant with data protection laws. For example, a social services employee could use the platform to remove sensitive data from a report, get an AI summary, and receive the complete result with the original data restored.

The county chose Liminal after a pilot phase and a full infrastructure review that included working sessions with Liminal's C-suite to understand the end-to-end data flow, how the system redacts versus masks depending on the use case, and how it behaves across different scenarios.

From pilot to enterprise-wide adoption

The rollout began as a soft launch with 150 users across several departments. After the pilot, the county's Department of Information Technology presented findings to executive management and agency leadership for approval, then shared the tool with employees through its Communications and Engagement Office. As of the report, 20 departments are using the platform. Hart noted that department users have become the greatest advocates, encouraging colleagues to adopt the tool. The county's philosophy is to gain buy-in rather than force adoption, with an eventual goal of making it an enterprise-wide requirement.

Separately, the county's AI-powered PWC311 service, known as Will, recorded nearly 90,000 resident interactions and about 40,000 questions around the same period, signaling broader AI adoption within county operations.

What this means for AI builders

For teams building AI products for regulated industries, the redact-rehydrate pattern is a practical alternative to approaches that require custom fine-tuning or data masking at rest. It allows staff to use general-purpose AI platforms without exposing sensitive data, and it preserves the full context of the prompt in the final output. The architecture is especially relevant for government, healthcare, legal, and financial services where data protection laws restrict what can be sent to third-party APIs.

The county's staged rollout also demonstrates a governance process worth studying: start with a small pilot, conduct a thorough infrastructure review, get executive approval, and rely on end-user advocacy to drive adoption. This reduces the risk of shadow AI while maintaining staff productivity.

Caveats and unknowns

The source evidence is limited to a single article, and neither Liminal nor county staff responded to requests for comment. Details on specific redaction rules, latency impact, cost, and how the system handles different types of sensitive data are not available. The county's approach is still in development, and the enterprise-wide rollout is not yet complete. Builders should treat this as a promising pattern rather than a fully validated solution until more independent details emerge.

FAQs

Liminal is described as providing AI total oversight and enterprise-wide compliance by redacting or masking sensitive data at the point of use before sending prompts to AI platforms, then rehydrating the data in the final answer. This keeps the prompt context intact while meeting data protection standards.

Sources

Latest Tech News