BackPrivacy and Data Protection
Privacy and Data Protection
Risk Domain
AI systems that memorize and leak sensitive personal data or infer private information about individuals without their consent. Unexpected or unauthorized sharing of data and information can compromise user expectation of privacy, assist identity theft, or cause loss of confidential intellectual property.
"Examining the ways in which generative AI systems providers leverage user data is critical to evaluating its impact. Protecting personal information and personal and group privacy depends largely on training data, training methods, and security measures."(p. 7)
Entity— Who or what caused the harm
Intent— Whether the harm was intentional or accidental
Timing— Whether the risk is pre- or post-deployment
Other risks from Solaiman et al. (2023) (11)
Bias, Stereotypes, and Representational Harms
1.1 Unfair discrimination and misrepresentationAI systemUnintentionalOther
Cultural Values and Sensitive Content
1.2 Exposure to toxic contentAI systemUnintentionalPost-deployment
Disparate Performance
1.3 Unequal performance across groupsAI systemUnintentionalOther
Financial Costs
6.1 Power centralization and unfair distribution of benefitsHumanIntentionalOther
Environmental Costs
6.6 Environmental harmHumanUnintentionalOther
Data and Content Moderation Labor
6.2 Increased inequality and decline in employment qualityHumanIntentionalPre-deployment