Automatically Deleting Confidential Data Before Sending to LLMs: Buying Focus with a $9 Physical Key—The Notion that ‘AI Risk Management’ is Expensive is Just a Misconception
Related Articles
“AI is Scary” but It’s Killing Small and Medium Enterprises
Let’s be clear. Right now, the biggest risk for small and medium enterprises is not “using AI.” It’s “not using AI.”
Fear of data leaks is prevalent. You never know what might happen. We don’t have security experts in-house—while you’re saying that and hesitating, the company next door is semi-automating their estimates, finishing meeting minutes in five minutes, and starting to delegate customer inquiries to LLMs.
So, how much does risk management cost? 3 million? 1 million?
The answer is “0 yen to 5,000 yen per month.” The tools are already available; you just don’t know about them.
—
Deleting Confidential Data “Before” Sending to LLMs—The Concept of Sanitizer
When small and medium enterprises use LLMs like ChatGPT or Claude in their operations, what is the most realistic risk? It’s not that “AI will go rogue.” It’s “an employee accidentally pasting customer personal information or internal confidential data into a prompt.”
This cannot be prevented by education alone. Humans make mistakes. Therefore, we need a system to stop it.
Sanitizer-type tools (specifically Microsoft Purview, Presidio, or LLM proxy services from various startups) automatically detect confidential information before sending data to LLMs and either mask or delete it.
The mechanism is simple:
- An employee uploads documents or text.
- The tool detects patterns like names, addresses, phone numbers, My Number, and credit card numbers.
- The relevant parts are replaced with “[REDACTED]” or pseudonyms.
- Only the cleaned data is sent to the LLM.
With just this, the risk of “accidental leaks” is drastically reduced.
What about the cost? With the open-source Presidio (from Microsoft), it’s 0 yen. Even for commercial SaaS proxies, there are plans available for around 2,000 to 5,000 yen per month for a team of ten. That’s less than 60,000 yen a year.
Consider the comparison. The damage when a data leak occurs—notification and response costs to customers, loss of trust, and potentially damages—can lead to losses of several million yen even for small and medium enterprises. For a monthly insurance premium of 3,000 yen, you can defuse that bomb. There’s no reason not to do it.
—
Physically Buying “Focus” for $9
There’s another interesting product with a completely different direction: a $9 (about 1,400 yen) NFC physical key.
This is more about “risk management on the human side of using AI” rather than AI risk itself.
Smartphones have social media and games installed. Notifications come in during work hours. You open them without thinking. Before you know it, you’ve lost 15 minutes—this is a quiet outflow of productivity happening in every company now that remote work has become the norm.
This NFC key physically locks specified apps. To unlock it, you need to hold the key up to your smartphone. If you keep the key in a drawer, you can physically block the temptation to “just take a quick look.”
Software-based screen time limits can be easily overridden. The physical key creates friction by requiring you to “get up and go get it.” This friction works. It implements what behavioral economics calls “default design” with just a $9 piece of hardware.
For a company of ten, buying one for everyone would cost only 14,000 yen. If we assume that each person can regain 30 minutes of focus per day, calculated at an hourly wage of 1,500 yen, that’s 330,000 yen worth of productivity regained each month. The return on investment is extraordinary.
—
EU’s Mandatory AI Labeling—Why It’s Not Just a Distant Problem
In 2025, the EU’s AI regulations (AI Act) will be gradually enforced. It will be mandatory to label images, audio, and text generated by AI to indicate that they are AI-generated.
“We don’t deal with the EU, so it doesn’t concern us”—is that really true?
For two reasons, this is not unrelated to local small and medium enterprises.
First, Japan is likely to follow suit. Just as the EU’s GDPR (General Data Protection Regulation) became a global standard, there is a trend for AI regulations to emerge from the EU and become a global standard. If you start implementing a system of “labeling AI-generated content” now, you won’t be caught off guard when regulations arrive in Japan.
Second, large companies in your supply chain will demand it. The push for compliance across the entire supply chain is accelerating. If you are asked, “Please show us your AI usage policy,” it would be problematic if you have nothing to present.
What about the cost of countermeasures? Tools that embed metadata in AI-generated content already exist. Some signature tools compliant with the C2PA standard are available for free. If you simply decide as an internal rule to “clearly state that documents and images created by AI are AI-generated,” the cost is 0 yen.
—
Summary of the Costs of “AI Risk Management”
Let’s organize this with specific numbers.
| Measure | Example Tools | Cost | Effect |
|---|---|---|---|
| Automatic masking of confidential data | Presidio (OSS) | 0 yen | Preventing information leaks to LLMs |
| Same (SaaS type) | Various LLM proxies | 2,000–5,000 yen per month | Same + management screen and logs |
| Physical lock for focus | NFC key | $9 (about 1,400 yen) each | Increased productivity |
| AI-generated labeling | C2PA-compliant tools | 0 yen or more | Regulatory compliance and reliability assurance |
| Formulating AI usage policy | Internal documents | 0 yen (just labor) | Governance foundation |
In total, a company with ten employees can implement a full set for 5,000 yen per month plus an initial cost of about 14,000 yen. That’s less than 70,000 yen a year.
This amount is negligible compared to the opportunity losses incurred by not using AI.
—
Ignorance is the Biggest Risk
The greatest barrier to the adoption of AI by small and medium enterprises is not technology or cost. It’s the information barrier of “not knowing what to do.”
You don’t need to hire a security expert. You don’t need to rely on expensive consultants. By simply implementing one of the tools mentioned above and writing a single internal rule, you can take the first step in risk management.
Large companies create specialized departments and spend tens of millions of yen building AI governance. Small and medium enterprises cannot do that, nor do they need to. “Start by trying one tool that costs 0 yen to 5,000 yen.” This is the correct approach to risk management for small and medium enterprises.
Conversely, companies that hesitate and say, “AI is scary,” thinking they are avoiding risk are actually taking the biggest risk. As competitors streamline their operations with AI, reduce costs, and increase response speed, doing nothing can become a fatal mistake.
Let’s start by trying. The tools are available. The prices are surprisingly low. You just didn’t know.
JA
EN