​​Securing Innovation: How We Protect NI Nigel AI™ End-User Data​

Overview

Artificial Intelligence tools are transforming how teams work—accelerating decision-making, automating routine tasks, and unlocking new insights. Nigel AI provides specialized tools for test and measurement teams. As with other AI engines, companies that want to protect their data must be selective in the tools they allow employees to use to ensure that the AI host is using the data responsibly. Organizations must ensure that proprietary data, intellectual property, and sensitive communications are protected from unauthorized access or misuse.

We recognize these concerns and have made security a cornerstone of our AI strategy. Nigel AI is designed not only to enhance productivity but also to uphold the highest standards of data protection and compliance. This document explores the key security features embedded in Nigel AI and how they align with our commitment to safeguarding customer and company information.​

Contents

​​Key Security Aspects of Nigel AI

Nigel Architecture 

Nigel has been architected from the top down with security and privacy in mind. In the most basic workflow, prompts entered by the end user in application software are sent to the Nigel Local Service (NLS) for formatting and encryption. The prompt is then sent to the Nigel Cloud Service (NCS) where the prompt is formatted into a query to the LLM, and a response is generated. 

Architecture of Nigel AI

Figure 1: Architecture of Nigel AI

The response is then encrypted and sent back to the Nigel Local Service, where it is decoded and presented to the end user. After the response is completed and the user ends the session, both the prompt and the response are deleted from the Nigel Cloud Service. The prompt is stored locally on the end-user’s machine, so the user has a list of the prompts sent for historical purposes. 

Nigel is built on Emerson’s secure and robust cloud operations platform. The underlying models used in Nigel are the OpenAI models from Microsoft. OpenAI has validation for all their models, and Microsoft provides security and data protections on top of these. These cloud-based technologies are already deployed globally and available to scale with any business needs. Communication between desktop software products (NI LabVIEW, NI TestStand, and others) and the Nigel Cloud Service uses encrypted traffic with web standard TLS. Communication between cloud components and the model are encrypted with mTLS. Both sides use signed certificates to authenticate.

Human Oversight in Nigel AI Operations

Nigel responds to human prompts and asks for confirmation before making suggested changes. Nigel does not autonomously control anything on the end user device. In Nigel workflows, the user is always in control, and Nigel acts as an AI assistant supporting the user. 

Nigel provides explanations for its responses and provides links to source files where possible. As with any AI-generated content, users are encouraged to always review any information or code Nigel generates before using it.

Nigel AI Performance and Response Times

Nigel has similar response times to Copilot and other Microsoft Azure technologies. Individual response times are dependent on company-specific networking configurations. Emerson does not currently publish benchmarks.

Nigel is available globally, as is the Microsoft Azure infrastructure on which it is built. These technologies have already been proven at scale. 

Data Stewardship  

Nigel is built on top of Microsoft’s Azure commercial tenant with access to Microsoft Azure Foundry Models. NI Nigel™ AI (Nigel) is purpose-built for addressing questions about test and measurement. Nigel has been taught test system design, methodologies, data analysis, and more, so you can get advice that is relevant to our industry. This test expertise is combined with knowledge of Emerson hardware and software. Queries outside of this domain, as much as possible, will result in Nigel telling the user that it is meant for asking questions about Test and Measurement. 

Customer searches are sent to servers for processing. A response is generated based on the existing database of information, but the customer’s search is not added to the AI for training. During a session, some customer search data is retained in the Nigel Cloud Service to accelerate responses and create a cohesive conversation. When the session is closed, all customer data is discarded. No personally identifiable information (PII) is stored by Nigel.  

​In some cases, the user’s query may initiate a search to ni.com. That search is anonymized. The ni.com website may keep these anonymized searches to improve the website operations.  

Data Protection 

​The data sent to Emerson is encrypted using HTTPS (TLS over HTTP) from the user’s desktop to the Azure cloud. TLS/mTLS is used to encrypt data in transit between components inside the Azure cloud. Data encryption is evaluated at each project iteration to maintain current security best practices. While it is stored by the server in the cloud, data at rest is encrypted with AES-256 encryption.  

Queries are sent to the cloud service from the local device in an encrypted transmission. Those queries are kept in the cloud service to provide responses in an agentic fashion—providing continuity from a question to follow up questions. When a session ends (a user closes the Nigel window), the queries are cleared and are not stored in the server. Microsoft separates all customer queries from each other by the use of responseIDs which are created using cryptographically secure mechanisms. Microsoft does not allow interactions from one responseID to another. That means that all data from each individual interaction with Nigel is separated from all other interactions using these responseIDs and users can only access and use data from their own interaction. All data for the queries and responses are encrypted using TLS or mTLS in transit and using AES-256 encryption while at rest. Additionally, Nigel is hosted on Microsoft Azure, which makes enterprise-grade privacy and security guarantees for the OpenAI APIs used by Nigel. Additionally, Microsoft’s terms are listed in their Services and Data Protection Addendum.  

The online Nigel Cloud Service does not store or retain any of the queries or responses it sends, after a session ends. Queries made by the user are stored locally on disk and can be retrieved or removed by the user at any time. No queries are ever used or retained by Emerson or Microsoft, and this is guaranteed in the terms of usage. Data for the queries and responses are encrypted using TLS prior to transmission. Notice that in some cases, a query response may provide a link to ni.com. ni.com does store queries made as part of their standard operations so they can improve common query response and web optimization, but these queries are stored as part of anonymized data and cannot be linked to specific people or accounts. 

Data Location 

Emerson deploys the Nigel application to a US-based Microsoft server. Under the Microsoft Global Standard Deployment, the LLM query may be handled by regional cloud centers. Queries are typically sent to the nearest regional server. For load balancing, Microsoft may route queries outside of the local regional server to other servers, which may not be in the country or continent. When this happens, Microsoft follows GDPR and other applicable regulations to protect the data. Microsoft’s terms for how data is handled in these scenarios are listed in their Services and Data Protection Addendum.

At this time, there is no way to guarantee that a query sent to Nigel will remain in a specific country or region. 

Data Use and Sharing 

​Emerson does not share Nigel query data with third parties, including Microsoft, in order to train Nigel generative AI models. Emerson will only share inputs or outputs with Microsoft when: (1) conversations are flagged for safety review to improve our ability to detect harmful content, enforce our policies, or advance AI safety research, or (2) you or anyone else have explicitly reported the materials to us for feedback (for example using our feedback mechanisms). 

Microsoft provides the underlying Azure OpenAI infrastructure for Nigel, but customer queries and responses are not stored by Microsoft for training purposes. Data transmission occurs through encrypted channels, and Microsoft’s access is governed by their standard Azure OpenAI service terms and Microsoft Products and Services Data Protection Addendum. No other third-party technology providers have access to customer interactions with Nigel beyond Microsoft’s role as the cloud infrastructure provider. 

Regulatory Compliance 

Nigel does not record or store any personally identifiable information (PII), and data being sent is completely anonymized. Emerson does not encourage nor ask for any use of personal data as part of the use of Nigel. If users choose to input personal data into Nigel, Emerson will treat it under our standard privacy and data security standards according to applicable law. Additionally, Microsoft documents GDPR compliance in their Services and Data Protection Addendum

Nigel is not classified as a high-risk AI system under EU Regulation 2024/1689 (AI Act). Nigel operates as a specialized advisory tool for test and measurement applications, providing information and code suggestions to engineers. It does not fall under the high-risk categories defined in Annex III of the AI Act, such as critical infrastructure, education assessment, employment decisions, law enforcement, or safety components. As an AI system used for technical advisory purposes, Nigel is subject to the transparency obligations under Chapter IV of the AI Act rather than the stricter requirements for high-risk systems. 

Nigel is available globally wherever Microsoft Azure services operate, but with some restrictions. Access is prohibited from countries subject to comprehensive US trade embargoes or sanctions. Additionally, certain AI features may be unavailable or limited in specific jurisdictions due to local AI regulations or technology provider restrictions. For example, some advanced AI capabilities may have reduced functionality in regions where underlying AI service providers face regulatory constraints. Emerson recommends checking with your local Emerson representative for region-specific availability and any applicable limitations before deployment. 

Ownership and Rights 

The end user retains full ownership of all content, data, and information submitted as input to Nigel. For outputs generated by Nigel in response to a user’s input, Emerson grants rights, title, and interest in those outputs to the end user and the terms for this are included in our AI T&C document. However, given that Nigel is based on AI technology, outputs provided may not be exclusive or unique. Other Emerson customers might generate similar outputs. In such cases, the rights granted to a single end user do not apply to outputs generated for other customers. For the exact terms and conditions of use, refer to Terms and Conditions for Generative AI Tools and Features at ni.com/legal

As with any AI-generated code, users are encouraged to always test and review any code Nigel generates before using it. Depending on the prompt used to generate the code, it may have performance, accuracy, or other issues, so testing is vital to ensure it works properly in the intended environment. You should also check that any open-source components comply with your license requirements. 

​The code suggestions Nigel generates are provided as-is. The end user is responsible for ensuring the suggestions are safe and appropriate for the specific use case. 

Access Control 

​Nigel users must log in using OpenID Connect (OIDC)-based authentication using the end user’s ni.com account. Access and refresh tokens are time-based and not subject to reuse or replay and stored in the cloud service. A reference session is passed back to the desktop system. 

​Emerson controls access to sensitive systems and data through our IAM provider. Access control for specific systems and data is limited by roles and named users where appropriate. Roles and access are reviewed and updated through a management lifecycle process. 

​Response Accuracy and Feedback 

​Product Feedback 

End users can provide feedback on any response by clicking the thumbs up or thumbs down icon in the response. 

Image of feedback in Nigel providing users links to like or dislike a response

Figure 2: Nigel Feedback Options

​When a user selects one of these feedback options, a pop-up window asks for additional information, and provides a reminder that data is being sent to Emerson. The query and the response are then sent to an Emerson engineer for manual review. Even in this workflow, where the user has chosen to send data back to Emerson, data is anonymized before being sent.

​An Emerson engineer may adjust the Nigel algorithm because of this feedback, but query data is never used to train the AI model. 

Emerson may collect additional telemetry data to monitor system performance and improve user experience. This includes interaction patterns, feature usage, response times, and error rates, but does not include the specific content of users’ queries or responses. All telemetry data is anonymized and used solely for product improvement and system reliability purposes. Users can review telemetry settings within their Emerson software configuration.

​Response Transparency

​When possible, responses from Nigel include a link to the source for the material, so that users can review the sources for accuracy and context. User queries are stored in a local logging file (at C:\ProgramData\National Instruments\AIAssistants\Logs\AIAssistant.txt) and can be retrieved by the end user’s company for review and control. The end user may review or delete the file. The file is not accessible or used by Emerson, including in Nigel.

Nigel is built on Emerson’s secure and robust cloud operations platform. The underlying models used in Nigel are the OpenAI models available from Microsoft. ​Nigel provides details about why responses are relevant to the query as part of its responses. ​No access to the LLM or log files is available.​

Responsible AI and Ethics: Ensuring Ethical and Fair Outputs

Nigel is designed specifically to answer questions about test and measurement systems. Nigel uses the default content safety mechanisms in Azure. The responses provided by Nigel are controlled by safety mechanisms in Azure, which can be found here: https://learn.microsoft.com/en-us/azure/ai-foundry/openai/concepts/default-safety-policies

​System Development Practices

Emerson’s Secure Development Lifecycle (SDL)

Product development at Emerson follows a formal Secure Development Lifecycle (SDL) that includes risk assessment, vulnerability management, and incident response. The Nigel development team is responsible for identifying, evaluating, and mitigating risks associated with the Nigel service. 

Emerson's SDL defines processes for security incident classification, response, disclosure, and customer notification. The company regularly scans for known vulnerabilities and applies security updates to Nigel cloud services. Security patches and fixes are disclosed and made available to customers at NI Security Resources.

Emerson is a CVE Numbering Authority (CNA) and publicly reports security vulnerabilities through the CVE program. A list of published CVEs is available on the NI security website. 

​Certifications 

To ensure consistent quality of development, and adherence to the principles in this paper, Emerson is ISO 9001-certified and regularly audits processes including the processes supporting Nigel. 

​Across all Emerson’s software and hardware development teams, including the development of Nigel, Emerson has adopted a secure development lifecycle (SDL) process into our engineering processes. 

​Emerson’s SDL includes assessing the risks of the application to ensure that the product is developed securely to address those risks. The SDL includes static and dynamic code testing. Emerson performs penetration testing, and results are used to improve the security of the application. Emerson regularly applies updates to the Nigel server to remove discovered vulnerabilities, with the update period depending on the criticality of the vulnerability.  

​Nigel is developed internally at Emerson, and Azure is the only third-party service used by Nigel. As part of Emerson’s SDL, all external service providers are reviewed for security prior to integration.

​The Emerson data centers which host the Nigel development are ISO 27001 certified.  

​System Robustness and Monitoring

​To ensure ongoing access to Nigel, Nigel is backed up and can be restored in case of a system incident. Customer searches are not stored in Nigel and are therefore not backed up. 

Emerson and Microsoft maintain disaster recovery plans for the cloud-based technologies that support Nigel.  ​Emerson does not provide any search or system monitoring tools. If this is needed, standard network monitoring tools are encouraged. Emerson does not provide guarantees of Nigel AI system availability or uptime.

​Incident Reporting 

Security concerns and incidents related to Emerson Test & Measurement products can be reported directly to Emerson at https://www.ni.com/security.

​Nigel AI Frequently Asked Questions

​​​Can Nigel integrate with our existing platforms (CRM, CMS, analytics tools)? What APIs or Interfaces are available?

Nigel is only available today from an interface inside of Emerson products. No API interfaces are available. 

​Does Nigel require internet access?

​Yes, Nigel requires an active internet connection. If a user doesn’t have internet access, they will not be able to run Nigel queries, but it will not impact any other features of Emerson software. 

​Can I use Nigel on-premise or in a dedicated cloud server?

​There is neither a private nor an on-premise solution at this time. These options are currently being explored along with other expanded functionality that can be viewed on our public software roadmaps page. ​

​Can Nigel be disabled or excluded from installation?

Yes. Nigel can be excluded from the installation by unchecking the "NI Nigel AI" box in the installation options. It can also be disabled by setting the Computer\HKEY_LOCAL_MACHINE\SOFTWARE\National Instruments\Nigel AI Advisor\DisableNigel registry key (DWORD (32-bit), 0 or 1) to 1.

​​How are third-party services managed? What is the impact of their failure?

​Microsoft is the only third-party service provider used by Nigel.  If Microsoft Azure experiences a global outage, Nigel would be unable to process new queries or log-in attempts until service is restored. However, Emerson software products such as LabVIEW and TestStand would continue to function normally.

​Emerson performs security assessments of external vendors before integration.

Nigel AI is independently developed and not affiliated, endorsed, or sponsored by Microsoft or OpenAI.
Microsoft, Azure, Azure OpenAI, Copilot, and Azure Monitor are trademarks of the Microsoft group of companies.
OpenAI is a trademark of the OpenAI Foundation.

Was this information helpful?

Yes

No