5.1 AI for Defence · Module 5 · Prompt Hygiene & Vendor Evaluation

Prompt Hygiene & Redaction

A concrete list of what never goes in — and how to sanitise what does.

Hygiene~12 min

The big idea

Prompt hygiene is the daily discipline that backs up the classification boundary. Per the DTA staff guidance, a public AI tool should never receive: anything OFFICIAL: Sensitive or above; personal information; third-party copyright; supplier commercial-in-confidence or pricing; Defence personnel or clearance data; source code for controlled systems; or recordings/transcripts of internal meetings. When in doubt, redact: roles instead of names, no identifying numbers, generalised dates, abstracted capability.

Key insight: The three DTA staff principles: protect privacy and safeguard government information; use judgement and critically assess outputs; and be able to explain, justify and own your advice and decisions.

What you'll see

What must never be entered, and how redaction works in practice.

The never-enter list (and how to redact)

Concrete categories to keep out. Tap to expand.

Key points to remember

Never enter classified, personal, commercial, capability, code or transcript data.
Redact to roles, remove numbers, generalise dates, abstract capability.
Follow the three DTA principles: protect, assess, own.
Where possible, do even safe tasks in your approved enterprise tool.