The fastest way to debug an AI agent is to log every prompt and response it ever sees.
It is also the fastest way to write a stranger's medical history into a log archive nobody can clean out.
When an agent does something baffling, you cannot ask it what it was thinking. The only evidence is a recording of what went in and out: the prompts (the text sent to the model), the replies, and every tool it reached for. That is tracing, and it does the job ordinary server logs do, just for model calls instead of web requests.
The key detail: a prompt has no fields. In a web app you know where the dangerous data sits, in the password field, the card number, the login token, so you strip those by name and you are done. A prompt is one blob of free text a person typed, and personally identifiable information (PII: a name, an email, a diagnosis) can sit anywhere inside it. Nothing is labelled.
So the scrubbing has to happen in your own code, before the text reaches your observability platform (the outside service that stores those traces). Not after. Once it lands there it has been copied into their storage, their backups, their search index, and removing it stops being a one-line change and becomes a support ticket.
This is not paranoia, it is the default. OpenTelemetry, the vendor-neutral tracing standard most of these tools speak, keeps prompt and response text switched off unless you deliberately turn it on, because it is likely to hold exactly that kind of personal detail.
The rule I'm keeping: redact at the door, not at the archive.
Quick check before you scroll: Should PII redaction happen before a prompt/response is sent to your observability platform, or after it's already stored there?
Full breakdown + the answer: frankduah.me/learnings/2026-09-07-logging-prompts-and-responses-without-leaking-data
New here? I post a bite-size AI / ML concept like this every day, follow me for the daily drop, and it compounds fast. Why I do it: https://lnkd.in/gK8knHDH
#LoggingPrompts #AI #LLM #AIAgents #MachineLearning
The answer
Before, redaction should run client-side, in your own application, so the sensitive data never leaves your process or reaches the third-party platform's servers at all.