CISO / Head of InfoSec
CISO / Head of InfoSec
What's actually going on
CattleGrid is the app your organisation uses to talk to AI providers (OpenAI, Anthropic, Google Gemini, Mistral) rather than going to each of those tools directly. You pick your model from the dropdown and type into the same kind of prompt box you'd expect from any AI chat tool. The difference is what happens to your message in the moment between you hitting send and it leaving the building.
It isn't there because IT doesn't trust you specifically. It's there because AI tools can't tell the difference between the text you meant to include and the text that was just sitting in the same paste. You copy in a paragraph of client correspondence for a quick summary, and the National Insurance number or account number in that paragraph goes with it. The tool processes all of it, because none of it was flagged as off-limits. This is common, not because people are careless, but because nobody had drawn a line before AI made it this easy to cross one without noticing.
What happens when you hit a rule
Every message is checked, what you typed, not the AI's reply, against rules your organisation has configured. You'll see the result directly in the app:
Block.
A notice card appears telling you the request didn't go anywhere, with a reason and a reference number. Nothing was forwarded to the AI provider.
Redact.
The sensitive part of your message is highlighted and replaced with a label, for example `[REDACTED: UK National Insurance Number]`, with the rule name shown if you hover over it. The rest of your message goes through as normal. The AI provider sees that something was removed, not what it was.
Warn.
An amber banner appears. Your message goes through unchanged, but the near-miss is logged.
Log.
Nothing visibly changes. The event is recorded quietly for your organisation's records.
(Separately, if your organisation's usage cap is close, you may also see a countdown notice while the app retries automatically. That's a usage limit, not a data-governance rule, and isn't about anything you typed.)
Whichever fires, nobody sits and reads your prompts afterwards. The content itself is never written to disk. That's the zero-retention architecture the whole system runs on. What gets kept is a record that an event happened: rule name, time, data type, not the data itself. You can see your own history of these under Rules Triggered in the app. That same record forms an audit trail your organisation can point to if a regulator asks how AI use is governed. It is not a transcript of what you typed.
What this means for you day to day
Once you know the shape of what gets caught, blocks and redactions stop being a surprise. The pattern is almost always the same: real names, real numbers, real client detail pasted in raw. Paraphrase it, or drop the specific numbers, and most requests go through without incident.
The upside is genuine. You can use CattleGrid for real work, drafting, summarising, researching, with Claude, GPT, Gemini or whichever model your organisation has enabled, without personally calculating the compliance risk of every prompt before you send it. That calculation is made for you, automatically, in under a millisecond, before the request leaves the building.
CattleGrid also includes secure team chat and direct messages, and AI-assisted team chat, for internal collaboration, encrypted according to your organisation's settings. Those work differently under the hood, since they're internal communication rather than outbound calls to an AI provider. This page is specifically about what happens in AI Chat, where the block/redact/warn behaviour above applies.
What this doesn't do
This is worth being direct about, because vague reassurance is worse than none.
- It does not read or store your prompts for review. There is nothing to review: the content is never written to disk.
- It does not build a profile of what you personally ask AI tools.
- It does not inspect or filter what the AI tool sends back to you. Only what leaves your organisation on the way there.
- It is not a substitute for judgement. It catches identifiable sensitive data against configured rules, not every conceivable way information could be handled carelessly.
If something feels off about a block, that's a conversation with your organisation's IT or compliance team, not a sign the system has flagged you personally.
Where to go from here
If a block doesn't make sense, or a rule seems to be catching things it shouldn't, your fastest route is your organisation's IT or compliance lead. They can see which rule fired and adjust it. If your organisation isn't running CattleGrid yet and you think it should be, forwarding this page is usually the fastest way to start that conversation.
- For the technical detail on how inspection works: Technical Resources
- For pricing: Pricing
- If you're the one who makes this decision as well as using the tools day to day (a fair number of people in smaller organisations are both), the free tier is a way to see it running before committing to anything: