AgentAnywhere Swaraj
Veil19 min readSee Veil →

The model needs the grievance. It does not need the Aadhaar number.

A department that puts AI to work on grievances, benefits and records is about to give a new reader access to citizens' data. Here is how to let that reader see the complaint and not the identifiers, what India's data-protection law and government security guidance ask of the department, and where masking stops being enough.

AgentAnywhere Research

Animated diagram: a citizen's grievance containing a PAN and an email address sits inside a government department's perimeter. At the perimeter Veil masks the two values, so the model receives the same complaint with the PAN shown as AB***F and the email as a***@e***.com. Below, a signed Trust Receipt lists who made the call, which fields were masked, under which policy and when.
FIG.66The complaint travels; the identifiers stay. Veil masks at the department's perimeter, the model receives the masked text, and a signed Trust Receipt records what was masked. Illustrative scene; the two mask forms are the ones Veil's captured output shows.

A Tuesday in the grievance cell

The scene that follows is illustrative. It describes no particular department.

The cell has a few hundred grievances open and four people to read them. Most are about money that did not arrive: a pension, a scholarship, a subsidy. People who are worried write everything down, because they have learned that a missing detail means a second visit. So a single complaint carries a name, an Aadhaar number, a mobile number, a bank account, a PAN and three sentences about a household's circumstances.

The department is trying an AI assistant that sorts each grievance into a category, pulls the history and drafts a reply for the officer to correct and sign. It works well enough that the officers want to keep it. Then the head of IT asks the only question that matters at this stage: when the assistant reads a grievance, where does the text go, and who else can read it there?

The supplier's answer is a paragraph in a contract. It says the data is not used for training and is deleted after thirty days. That may be true. The department has no way of showing it to an auditor, a court or the citizen. And the model never needed the Aadhaar number to work out that this is a delayed-pension complaint.

The useful question is not whether you trust the model's operator. It is what the operator ever received.

How Veil works in a department

Veil sits in the path of every call an AI agent makes, at the point where text leaves the department's systems. The same four steps happen each time. We described them for a general reader in Mask it before the model sees it; this is what they mean in an office that serves citizens.

  • Classify, on every call

    Veil detects personal, financial and regulated fields inline: the classes its page lists are names, contacts, account and card numbers, health identifiers, and the fields your own policy designates. A scheme's beneficiary ID is a field you designate.

  • Mask, field by field

    Policy chooses per field. Redact what nothing downstream needs: the value is replaced before the call goes out. Tokenise what a caseworker must get back: a deterministic token stands in, and unmasking is policy-gated and itself logged as a Trust Receipt. Reversible tokenisation is not on by default; it is switched on per deployment.

  • Enforce, outside the application

    Masking is applied at the egress point, not coded into each assistant. On the AgentAnywhere platform the Agent Universal Gateway enforces it under policy that Custodian defines, so a new agent inherits the rule instead of having to remember it.

  • Prove, with a record

    Every mask and unmask is logged as a Trust Receipt: who, what, under which policy, when. It is signed and versioned and can be exported for auditors. It records what was masked; a value that was not detected leaves no receipt.

What a run on synthetic records shows

This is not an illustration. It is a run of Veil's pattern detectors on synthetic records on 7 October 2026, on the version of Veil deployed that day, at two settings: the "fast" depth meant for the inline path, and the default "balanced" depth. No model was loaded. We wrote every record for the run; none of it is anyone's data. Where an input value could coincide with a real person's number, part of it is hidden with ▒ before publishing. Outputs are as Veil produced them: asterisks are its masks, and where it keeps the last four digits of a value they are visible. Where Veil left such a value in clear, the same part is hidden with ▒ in the output too, so a ▒ in an output means Veil did not mask that value.

Veil pattern detectors · synthetic records · 7 October 2026
RECORD · A citizen's grievance to a government department (English)

IN (synthetic)
My name is Sunita Verma. My old-age pension has not been credited since July. Aadhaar 9999 ▒▒▒▒ ▒▒▒▒, PAN ABCDE1234F, mobile +91 98▒▒▒ ▒▒▒▒▒, email sunita.verma@example.com. Date of birth 14 March 1957. Address: 12 Gandhi Road, Rampur.

OUT at depth "fast" (the set meant for the inline path)
My name is Sunita Verma. My old-age pension has not been credited since July. Aadhaar ********, PAN AB***F, mobile ********1234, email s***@e***.com. Date of birth 14 March 1957. Address: 12 Gandhi Road, Rampur.

OUT at depth "balanced" (the default)
My name is ********. My old-age pension has not been credited since July. Aadhaar ********, PAN AB***F, mobile ********1234, email s***@e***.com. Date of birth 14 March 1957. Address: 12 Gandhi Road, ******.

▒ hidden by us for publication · * masked by Veil, as produced · run of 7 October 2026, Veil commit 700ca8b, the version deployed that day · no model loaded

Reading the run honestly

What was masked. At both depths: the Aadhaar number, the PAN, the email address and the mobile number, which the record writes with a country code and a space and which keeps its last four digits. At the default depth also the name that follows “My name is”, and the name of the town.

What was not. The date of birth and the street line of the address were left in clear at both depths. At the fast depth the name and the town were not masked either: names and places are not in the fast set.

What to take from it. An identifier with a fixed shape and a checksum, such as an Aadhaar number, is the easy case. A date, an address or a sentence that identifies someone by circumstance is not, and no pattern will make it one. A department should decide which fields its policy designates, test them on its own sample, and treat the free-text narrative as personal data whatever is masked inside it.

Keeping it inside the perimeter

For a public body the location of the masking step matters as much as the masking. It has to happen before the text crosses a boundary the department does not control.

Where it runs

Veil deploys standalone, in front of the agents and models a department already uses, or natively in the AgentAnywhere platform. No platform migration is needed to add the masking step.

Public-sector deployments run on the department's own tenant or hardware, in its own facility, and Swaraj runs the whole arrangement air-gapped inside the boundary. Customer data never transits ShepHertz infrastructure, including during support sessions. Those are the words of our Trust Center, and we do not stretch them here.

What crosses

For a designated field that is detected, only the masked form. The raw value stays where it was. If the model sits outside the department, its operator holds masks and tokens for those fields in its prompts and logs. A value that is not detected crosses as written, which is why the run above matters.

Getting a value back is a decision, not a default. Reversible tokenisation is switched on per deployment, unmasking is policy-gated, and each unmask is itself logged as a Trust Receipt.

What it changes for the department

The question for the supplier changes. Instead of asking a model provider to promise what it does with citizens' identifiers, the department can show what the provider was sent. A promise needs trust. A record of what crossed can be checked.

A leak elsewhere costs less. If a prompt log outside the department is exposed, the designated fields that were detected are masks in it. That is a smaller incident than a log of raw identifiers. It is still an incident: the narrative of a grievance can identify a person without a single number in it.

Part of the audit is already written. When someone asks what was masked for the assistant in March, the answer is a set of receipts written at the time. They show each mask and unmask. They do not show what the model received, so the department still needs its own record of what was sent.

Officers keep their tool. The assistant goes on classifying and drafting. What it loses is information it did not need.

Which rules apply, and where masking helps

One row per rule. “If applicable” is meant literally: two of these do not apply to most departments, and the row says so. Dates are as the texts stated them on 7 October 2026.

The ruleWho it applies toWhat it asks forWhere masking at the perimeter helpsWhat masking does not cover
The rule: Digital Personal Data Protection Act, 2023, section 8(4) and 8(5), and DPDP Rules, 2025, Rule 6 12Every data fiduciary. The Act's definition of a person includes the State, so a department is covered unless it is an instrumentality the Central Government has notified under section 17(2)(a). These duties come into force eighteen months after the Rules were published in November 2025: May 2027.Reasonable security safeguards to prevent a personal data breach, including for processing done on the department's behalf by a data processor. Rule 6 lists, as examples of data security measures, encryption, obfuscation, masking or virtual tokens mapped to the personal data.Masking and virtual tokens are two of the measures the rule names. Applied before the call, they also limit what a processor running the model ever holds.The rest of Rule 6: access control, logs and their one-year retention, backups, and security terms in the contract with the processor. The rule gives masking as an example, not as a sufficient measure.
The rule: DPDP Act section 7(b) and DPDP Rules, 2025, Rule 5 with the Second Schedule 12The State and its instrumentalities when they process personal data to provide a subsidy, benefit, service, certificate, licence or permit. In force from May 2027.Processing that follows the Schedule's standards, among them: limited to the personal data necessary for the purpose, and protected by reasonable security safeguards, including when a data processor does the work.It keeps identifiers the model does not need out of the model's input, which is the “necessary” test applied to one more reader.The other standards: lawful processing, accuracy, retention, telling the citizen how to reach the department and exercise their rights, and accountability.
The rule: CERT-In, Guidelines on Information Security Practices for Government Entities (2023) 4Ministries, departments and offices of the Government of India, their attached and subordinate offices, and the institutions, public sector enterprises and agencies under them. A State department should check what its own government has adopted.Among much else: identify and classify sensitive and personal data, encrypt it in transit and at rest, deploy data-loss prevention, and see that data a vendor collects or processes is protected and not shared without agreement.Classification on the AI path, and less personal data in a vendor's hands to protect.Encryption and data-loss prevention, which the guidelines ask for by name. Masking is a further measure, not a replacement for either.
The rule: Aadhaar (Sharing of Information) Regulations, 2016, regulation 6 6Any individual, entity or agency in possession of Aadhaar numbers.Keep Aadhaar numbers and any record containing them secure and confidential; do not publish them; redact them before making any database or record public.It is a way of keeping the number confidential from one more system. In the run above the Aadhaar number was masked at both depths.How Aadhaar numbers are collected, stored and used in the department's own systems, and the separate duties of entities that authenticate with UIDAI.
The rule: CERT-In Directions of 28 April 2022 under section 70B(6) of the IT Act 5Service providers, intermediaries, data centres, bodies corporate and government organisations.Keep logs of ICT systems for a rolling 180 days within Indian jurisdiction, and report listed cyber incidents to CERT-In within six hours of noticing them.It does not. We list it so that nobody assumes it does: masking the prompt changes nothing about where logs are kept or how fast an incident is reported.All of it. A Trust Receipt is a record of masking, not a substitute for system logs.
The rule: Reserve Bank of India directionsThe entities each direction names: for example, the outsourcing directions cited in the banking post apply to commercial banks. A government department is not among them.They do not bear on a department as such. A department's banking partner carries them; see the banking post.Not applicable.Not applicable.
The rule: EU General Data Protection Regulation, Articles 3, 25, 32 and 44 to 46 9Processing in the context of an establishment of a controller or processor in the Union, and processing of personal data of people who are in the Union by a controller or processor not established there, where it relates to offering them goods or services or to monitoring their behaviour (Article 3). A European counterpart may also pass personal data to a department only under the Regulation's transfer rules. Whether either applies is for the department's legal adviser.Data minimisation, data protection by design, and security of processing; Articles 25 and 32 both name pseudonymisation as a measure. Transfers to a third country need an adequacy decision or appropriate safeguards, and the Commission's list of adequacy decisions does not include India 12.Tokenising identifiers before a model sees them is pseudonymisation in the Regulation's sense, provided the key is kept separately and protected.Pseudonymised data that could be attributed to a person by the use of additional information is information on an identifiable person (Recital 26). The Regulation continues to apply to it.
The rule: EU Artificial Intelligence Act, Regulation (EU) 2024/1689 1011For providers and deployers established or located in a third country, the Act applies where the output produced by the AI system is used in the Union (Article 2(1)(c)).For information: the Act treats AI used by public authorities to decide eligibility for essential public benefits as high-risk. Those obligations were moved in July 2026 and now apply from 2 December 2027.It is not what the Act asks for.Everything the Act asks of a system within its reach.

This table states what the texts say and where one control helps. It is not legal advice. Whether and how a rule applies to your department is a question for your own legal adviser.

What the Government has said about AI tools in departments

There is no law that tells a department it may not use AI. In a written answer in the Rajya Sabha on 27 March 2025, the Ministry of Personnel, Public Grievances and Pensions said there is no specific prohibition on the use and adoption of AI-based tools by government departments, and that government functionaries are expected to exercise due diligence and caution to ensure the safety, security and confidentiality of public information while using any digital technology or platform 7.

The India AI Governance Guidelines published by the Ministry of Electronics and Information Technology in November 2025 take the same line from the other side. They describe voluntary measures as not legally binding, and they say that many AI risks are already governed by existing law, giving the use of personal data under the Digital Personal Data Protection Act as an example 8.

Put together, the position is plain. A department may use these tools. The confidentiality of what it puts into them is the department's responsibility, under laws that already exist. Our earlier guide, The DPDP Rules and your AI agents, covers the wider list of duties; masking is one item on it.

What Veil does not do

It does not make data anonymous. A token that the department can turn back into an Aadhaar number is still that citizen's personal data, in the department's hands and in law. What Veil changes is who receives the raw value.

It does not mask all personal data, and nobody should write that it does. The run above left a date of birth and a street address in clear. A grievance that says “my husband died in March and I am the only earner” identifies a person without containing a single identifier.

It does not decide lawfulness. Notice, purpose, consent or a legitimate use, retention, the citizen's rights and breach reporting are the department's duties with or without masking.

It does not replace access control, logs or encryption. The rules in the table ask for those by name.

It is not a shield against manipulated input. A grievance can carry text written to steer the assistant. That is a different control, Kavach, on the same call.

It is shown here on text. The Veil page and the run in this post show typed text being masked. We make no claim in this post about scanned forms, handwriting, photographs or audio. One line of the wider run was in Hindi; that is an example, not a claim about every Indian language.

It is not a certification of anyone's deployment. ShepHertz operates a control environment credentialed for SOC 2, ISO 27001, HIPAA and GDPR. These are advisory alignments to inform your own assessment, not certifications of your deployment or binding regulatory claims. And this post describes a product and public rules. It does not describe a deployment in any ministry, department or State, and nothing in it should be read as an endorsement by one.

Frequently asked questions

Can a government department in India send citizens' personal data to an AI model?

No law specifically prohibits it. In a written answer in the Rajya Sabha on 27 March 2025 the Government said there is no specific prohibition on AI-based tools in departments, and that functionaries are expected to exercise due diligence and caution to ensure the safety, security and confidentiality of public information 7. A practical way to meet that expectation is to mask identifiers before the text leaves the department's systems, so that the identifiers that are detected do not reach the model, and to keep a record of what was masked.

Does the DPDP Act apply to government departments?

Yes, in general. The Act's definition of a person includes the State 1. A department is relieved of the Act only if it is an instrumentality the Central Government has notified under section 17(2)(a) for the interests listed there, and section 17(4) separately relieves the State of the erasure provisions and, where no decision affecting the person is involved, of the correction provision. The duty to take reasonable security safeguards under section 8(5) remains. For subsidies, benefits, services, certificates, licences and permits, Rule 5 and the Second Schedule of the DPDP Rules, 2025 set the standards. These provisions come into force in May 2027 2. Confirm how they apply to your department with your own legal adviser.

Do the DPDP Rules require masking?

They name it. Rule 6 of the DPDP Rules, 2025 requires reasonable security safeguards and lists, as examples of data security measures, encryption, obfuscation, masking or the use of virtual tokens mapped to the personal data 2. Masking is one of the named examples, not a measure that is sufficient on its own: the same rule also requires access control, logs kept for a year, backups and security terms in contracts with processors. Rule 6 comes into force eighteen months after the Rules were published in November 2025, which is May 2027.

Is masked or tokenised data still personal data?

If it can be linked back to a person, yes. A token that the department can reverse is still that citizen's personal data. Under the EU's General Data Protection Regulation the same idea is written down: pseudonymised data that could be attributed to a person by the use of additional information is information on an identifiable person 9. Masking reduces what the model and its operator ever receive. It does not take the data outside any data-protection law.

Does Veil mask Aadhaar numbers?

In a run of Veil's pattern detectors on synthetic records on 7 October 2026, an Aadhaar number was masked at both depth settings, written in Latin digits and in Devanagari digits. A run on synthetic records is an example, not a guarantee about your data. In the same run a date of birth and the street line of an address were left in clear. Bring a sample of your own records and we will run it with you.

Can Veil run entirely inside a government data centre?

Yes. Veil deploys standalone in front of the agents and models you already run, or as part of the AgentAnywhere platform, where Swaraj runs it air-gapped inside your boundary. Public-sector deployments run on your own tenant or hardware, in your own facility, and customer data never transits ShepHertz infrastructure, including during support sessions.

Do Reserve Bank of India or European Union rules apply to a government department?

Reserve Bank directions apply to the entities each direction names, such as commercial banks; a department is not among them. The EU's General Data Protection Regulation applies to processing by an establishment in the Union, and to processing of personal data of people who are in the Union where it relates to offering them goods or services or monitoring their behaviour 9. The EU AI Act applies to a provider or deployer in a third country where the output produced by the system is used in the Union 10. Whether either reaches a particular department is for its legal adviser.

Sources

The texts as they stood on 7 October 2026. Where a text gives a date of application, the post repeats it as written.

  1. 1Parliament of India: Digital Personal Data Protection Act, 2023 (No. 22 of 2023), assented to on 11 August 2023; sections 2(s), 7(b), 8, 17 and the Schedule.
  2. 2Ministry of Electronics and Information Technology: Digital Personal Data Protection Rules, 2025, G.S.R. 846(E), Gazette of India, Extraordinary, November 2025; Rules 1, 5, 6 and the Second Schedule. The notification bringing the Act's own sections into force in the same three stages is G.S.R. 843(E) of the same date.
  3. 3Press Information Bureau: DPDP Rules, 2025 backgrounder, 17 November 2025.
  4. 4CERT-In: Guidelines on Information Security Practices for Government Entities, 2023; sections 7.1 and 8.6.
  5. 5CERT-In: Directions under section 70B(6) of the Information Technology Act, 2000, 28 April 2022.
  6. 6UIDAI: Aadhaar (Sharing of Information) Regulations, 2016, as updated to 21 August 2025; regulation 6.
  7. 7Rajya Sabha: Unstarred Question No. 3153, answered on 27 March 2025.
  8. 8Ministry of Electronics and Information Technology: India AI Governance Guidelines, November 2025.
  9. 9European Union: Regulation (EU) 2016/679, General Data Protection Regulation, applicable from 25 May 2018; Articles 3, 4(5), 25, 32, 44 to 46 and Recital 26.
  10. 10European Union: Regulation (EU) 2024/1689, Artificial Intelligence Act, 13 June 2024; Article 2(1)(c) and Annex III, point 5(a).
  11. 11European Union: Regulation (EU) 2026/1744, 8 July 2026, amending Article 113 of the AI Act.
  12. 12European Commission: Adequacy decisions, list as shown on 7 October 2026.
TopicsAI in government India data protectioncitizen data maskingDPDP Act government departmentsAadhaar masking AIgrievance redressal AI privacyPII redaction for public sector AI

Written by

AgentAnywhere Research

The team that builds the platform and the models

AgentAnywhere Research writes about the platform, the model families and the trust layer we build and run in India. Where a figure is ours, it says what it covers; where something is a demonstration, it says so.

All articles →