Posts

Protecting Sensitive Data from AI Agents with MySQL Dynamic Data Masking

Image
Article Overview AI agents now query production databases directly. When a support bot, a reconciliation job, or a fraud pipeline runs a SELECT, the result does not stay inside your application. It is turned into text, placed in a prompt, and sent to a model endpoint that you do not control. From there it may land in logs, caches, or even training data. A grant that is harmless for a careful human becomes a data flow that leaves your network. This article shows a practical way to solve that. The goal is simple: let an AI agent do real support work — find the customer, read their orders, check the open ticket, write a reply — while the database itself makes sure that no full card number, email address, phone number, or government ID ever reaches the model. It is a hands-on database article, with SQL, Python, and real output captured from a MySQL 8.4 instance. Table of Contents Why agent access is different The scenario What MySQL actually provides The architecture Building the masking l...