BackPrivacy Invasion
Privacy Invasion
Risk Domain
AI systems that memorize and leak sensitive personal data or infer private information about individuals without their consent. Unexpected or unauthorized sharing of data and information can compromise user expectation of privacy, assist identity theft, or cause loss of confidential intellectual property.
AI systems typically depend on extensive data for effective training and functioning, which can pose a risk to privacy if sensitive data is mishandled or used inappropriately(p. 2)
Entity— Who or what caused the harm
Intent— Whether the harm was intentional or accidental
Timing— Whether the risk is pre- or post-deployment
Other risks from Habbal et al. (2024) (6)
Bias and Discrimination
1.1 Unfair discrimination and misrepresentationAI systemUnintentionalPost-deployment
Society Manipulation
4.1 Disinformation, surveillance, and influence at scaleAI systemIntentionalPost-deployment
Deepfake Technology
4.1 Disinformation, surveillance, and influence at scaleHumanIntentionalPost-deployment
Lethal Autonomous Weapons Systems (LAWS)
4.2 Cyberattacks, weapon development or use, and mass harmAI systemIntentionalPost-deployment
Malicious Use of AI
4.3 Fraud, scams, and targeted manipulationHumanIntentionalPost-deployment
Insufficient Security Measures
2.2 AI system security vulnerabilities and attacksHumanIntentionalPost-deployment