The CreatorCon Call for Content is officially open! Get started here.

Ashley Snyder
ServiceNow Employee
ServiceNow Employee

For an overview on how you can protect sensitive data when using AI Agents and Now Assist, see this video:

 

 

Q: Why is sensitive data masking important when using ServiceNow's generative AI products such as Now Assist and AI agents?

A: In modern enterprise environments, organizations handle troves of sensitive data including personally identifiable information (PII). When using generative AI products, sensitive data masking is crucial for protecting confidential information during inference and model training (when customers are eligible and opted-in). Sensitive data masking helps prevent exposure of sensitive data to language models, ensuring compliance with data privacy regulations such as GDPR, CCPA, and HIPAA. By masking sensitive data, organizations can maintain customer trust when using generative AI products.

 

Q: What solutions does ServiceNow offer to mask sensitive data when using generative AI products?

A: Data Privacy for Now Assist supports masking sensitive data in generative AI use cases using real-time anonymization (RTA) techniques and replaces our previous Sensitive Data Handler solution in the Yokohama release for masking sensitive data in generative AI products. It is integrated into the Generative AI Controller and works with all LLMs. Data Privacy for Now Assist uses configurable data discovery patterns to anonymize PII for generative AI and AI Agent use cases when sending data to any AI model for processing. When masking PII and other sensitive data, placeholder text, along with any defined techniques, is sent with the prompt. The placeholder text is replaced with the original text after the response has been received in the instance. This two-way masking method ensures your users see the correct values in the instance and the generative AI model is not exposed to any sensitive information.

 

The Sensitive Data Handler is available for conversational use cases within a customer's instance. During an Agent Chat or Virtual Agent conversation, the agent or requester may accidentally enter sensitive data. The Sensitive Data Handler detects and masks the sensitive data so it is not viewed by the agent or requester. The Sensitive Data Handler can also collect sensitive data as part of a business process, such as user authentication.

 

We recommend Now Assist customers enable both solutions to provide full data masking coverage for both conversational use cases and information sent to large language models for the current release.

 

Q: What types of sensitive data can Data Privacy for Now Assist mask in Generative AI?

A: Data Privacy for Now Assist can mask various types of sensitive data, including personally identifiable information (PII) and other customer-defined sensitive data. It uses Privacy policies and data patterns to identify sensitive data.

 

Q: How can I configure Data Privacy for Now Assist to handle sensitive data in my ServiceNow instance?

A: To configure Data Privacy for Now Assist, refer to the product documentation for detailed instructions.

 

Q: Are Data Privacy for Now Assist and the Sensitive Data Handler enabled and configured by default?

A: No, Data Privacy for Now Assist and the Sensitive Data Handler are not turned on and configured by default. Customers need to enable and configure these features according to their specific needs and requirements.

 

Q: Will my existing Sensitive Data Handler regex patterns for masking sensitive data be migrated to Data Privacy for Now Assist?

A: Yes, for customers who have configured Sensitive Data Handler regex patterns to mask sensitive data for Generative AI, these patterns will be automatically migrated to Data Privacy for Now Assist.

 

Q: What are the best practices for implementing sensitive data masking with Data Privacy for Now Assist?

A: Best practices include regularly reviewing and updating data masking policies, ensuring that all sensitive data is identified and masked, and conducting regular audits to verify the effectiveness of the masking techniques. Integrate data masking into your existing workflows and address user concerns to ensure a smooth implementation.

 

Q: How does Data Privacy for Now Assist help with regulatory compliance?

A: Data Privacy for Now Assist helps organizations comply with data protection regulations by ensuring that sensitive information is not exposed in non-production environments. It provides tools and techniques to manage sensitive data according to regulatory requirements, reducing the risk of non-compliance and potential legal consequences.

 

Q: Can Data Privacy for Now Assist be customized for specific organizational needs?

A: Yes, Data Privacy for Now Assist offers customizable options to fit your organization's specific needs. Administrators can define privacy policies, patterns, and privacy techniques.

 

Q: How can I monitor the effectiveness of sensitive data masking with Data Privacy for Now Assist?

A: Customers can test data masking for custom skills in Now Assist Skill Kit, and review flow logs to verify real-time data masking at this time.

 

Q: How does the Sensitive Data Handler in ServiceNow help with masking sensitive data for conversational use cases?

A: The Sensitive Data Handler in ServiceNow helps mask sensitive data for conversational use cases by applying masking rules in real time during interactions. It ensures that sensitive information is protected during conversations with AI agents, maintaining privacy and compliance while providing a seamless user experience.

 

Q: What is the difference between data masking in model training versus inference in ServiceNow?

A: Data sharing for model training is an optional program where ServiceNow uses industry-standard and in-house tooling to anonymize data. We list the out-of-the-box data that we will cleanse and anonymize in our Data Sharing and Model Development FAQs (Support login required). In addition to our data types, customers can configure Data Privacy for Now Assist to mask additional data that falls outside of our default categories for data extraction via the Data Extraction channel.

 

In contrast, data masking during inference is a real-time process that protects sensitive data as it is being processed by the AI model and is configured by the Now Assist data channel in Data Privacy for Now Assist.

 

Q: Is Data Privacy for Now Assist included in Now Assist licensing?

A: Yes, Data Privacy for Now Assist is included in the Now Assist licensing. However, for other features related to ServiceNow Data Privacy, a ServiceNow Vault license may be needed.

 

Q: What should customers who want to mask data within the ServiceNow instance use?

A: Customers who want to mask data within the ServiceNow instance should use ServiceNow Vault Data Privacy. This solution provides robust data protection capabilities, ensuring that sensitive data remains secure and compliant with regulatory requirements.

 

Q: What is the architecture for Now Assist, and how does it handle data privacy?

A: The architecture for Now Assist encompasses customer-managed software, ServiceNow-managed and customer-managed models, data, and compute. Data Privacy for Now Assist is integrated into the Generative AI Controller and works with all LLMs to ensure that sensitive data is masked during real-time inference. This integration helps maintain data privacy and compliance throughout the AI processing workflow.

 

Q: What is the difference between ServiceNow Data Privacy and Data Privacy for Now Assist?

A: ServiceNow Data Privacy is a broader feature that provides robust data protection capabilities across the ServiceNow platform, ensuring that sensitive data remains secure and compliant with regulatory requirements. It includes features like data anonymization, encryption, and access controls to protect data throughout its lifecycle.

 

Data Privacy for Now Assist, on the other hand, is specifically designed to enhance sensitive data protection in Generative AI applications. It integrates with the Generative AI Controller to provide real-time anonymization (RTA) of sensitive data during interactions with AI models. It focuses on masking data during inference to prevent exposure of sensitive information while using generative AI features like Now Assist and AI agents.

 

This comparison highlights the differences in scope, use case, and functionality between ServiceNow Data Privacy and Data Privacy for Now Assist, helping users understand when and how to use each feature.

 

Feature / Capability

ServiceNow Data Privacy

Data Privacy for Now Assist

Scope

Broad platform-wide data protection

Specific to Generative AI applications

Primary Use Case

General data security and compliance

Real-time data masking during AI interactions

Integration

Across the Now Platform

Integrated with Generative AI Controller

Data Anonymization

Real-time and jobs for data that resides in the Now Platform.

Real-time anonymization (RTA) for AI inference

Customization

Configurable for various data types and compliance needs

Customizable for specific AI use cases and data patterns

Regulatory Compliance

Comprehensive compliance with data protection regulations

Focused on compliance during AI interactions

Data Handling

Manages data lifecycle, including storage and access

Focuses on data masking during real-time AI processing, evaluation for Now Assist Data Kit, and data extraction for data-sharing program for model development.

 

Our guidance is for customers to explore both product offerings when using AI products to meet the end-to-end needs of protecting data in the Now Platform and during AI processing.

 

Product Documentation

  1. Data Privacy for Now Assist

  2. ServiceNow Data Privacy Documentation

  3. Sensitive Data Handler

Version history
Last update:
‎03-20-2025 07:01 AM
Updated by:
Contributors