Framework · AI Data Risk
The LLM Exposure Curve
PII and business-intelligence risk mapped across the seven bowtie-funnel lifecycle stages — an interactive view of exactly when sensitive data enters your AI stack, from anonymous awareness traffic to fully sensitive expansion data, and what each stage demands to stay protected.
PII & Business Intelligence Risk by Lifecycle Stage
What it is: An interactive chart showing exactly when PII and business intelligence cross each risk threshold across your customer lifecycle.
Why it matters: PII enters your AI stack as early as Stage 2 — most teams don't know until it's too late.
Why protect it: Unmasked data trains models, leaks across sessions, and creates legal exposure at your most sensitive stages.
What you can do: Mask PII early, limit what your models can see, and control what they're allowed to store.
PII / Security Sensitivity
LLM Data Risk by Customer Lifecycle Stage
- Stage 1: Awareness
- Risk Level: Anonymous. Data State: Public Cloud Content. PII Sensitivity: 0%. Public web traffic, high-level marketing content, open server logs. Zero liability. No authenticated sessions.
- Stage 2: Education
- Risk Level: Trace PII. Data State: Light Form & Cookie Captures. PII Sensitivity: 5%. Newsletter signups, ungated assets, cookie-based intent signals. GDPR consent layer active.
- Stage 3: Selection
- Risk Level: Low. Data State: Standard SaaS / CRM Ingestion. PII Sensitivity: 20%. Corporate emails, names, titles via standard public CRM APIs. OAuth 2.0 flows.
- Stage 4: Mutual Commit
- Risk Level: Medium. Data State: Secure Ephemeral Cloud. PII Sensitivity: 50%. NDAs, pricing redlines, draft security agreements via TLS-encrypted tunnels. No persistent LLM memory.
- Stage 5: Onboarding
- Risk Level: High. Data State: Local-First Processing. PII Sensitivity: 85%. System credentials, production configurations, employee rosters inside self-hosted durable execution environments.
- Stage 6: Retention
- Risk Level: Very High. Data State: Persistent Usage Analytics. PII Sensitivity: 92%. Product telemetry, feature adoption signals, health scores, and support history in customer-isolated containers. Strict model context boundaries prevent cross-account data leakage.
- Stage 7: Expansion
- Risk Level: Critical. Data State: Zero-Retention Sovereign Files. PII Sensitivity: 100%. Revenue telemetry, application data logs, financial PII via encrypted flat files under strict internal RBAC.
01
Active Stage
Data State
Architectural Notes
PII Sensitivity
Data Liability
Risk
Zero → Critical
Know what your AI stack can see
Get an AI Design Sprint of where PII enters your GTM systems and which lifecycle stages need the strongest protection — or read the playbook behind the framework.