Skip to main content
Home/Risks/Bengio2025/Risks to privacy

Risks to privacy

Sub-category
Risk Domain

AI systems that memorize and leak sensitive personal data or infer private information about individuals without their consent. Unexpected or unauthorized sharing of data and information can compromise user expectation of privacy, assist identity theft, or cause loss of confidential intellectual property.

"General- purpose AI systems can cause or contribute to violations of user privacy. Violations can occur inadvertently during the training or usage of AI systems, for example through unauthorised processing of personal data or leaking health records used in training. But violations can also happen deliberately through the use of general- purpose AI by malicious actors; for example, if they use AI to infer private facts or violate security."(p. 139)

Supporting Evidence (3)

1.
"General- purpose AI sometimes leaks sensitive information acquired during training or while interacting with users. Sensitive information that was in the training data can leak unintentionally when a user interacts with the model. In addition, when users share sensitive information with the model to achieve more personalised responses, this information can also leak or be exposed to unauthorised third parties."(p. 139)
2.
"Malicious actors can use general- purpose AI to aid in the violation of privacy. AI systems can facilitate more efficient and effective searches for sensitive data and can infer and extract information about specific individuals from large amounts of data. This is further exacerbated by the cybersecurity risks created by general- purpose AI systems (see 2.1.3. Cyber offence)."(p. 139)
3.
"General- purpose AI poses various risks to privacy. These are very broadly categorised into: ● Training risks: risks related to training and the collection of data (especially sensitive data). ● Use risks: risks related to AI systems’ handling of sensitive information during use. ● Intentional harm risks: risks that malicious actors will apply general- purpose AI to harm individual privacy (see Figure 2.11)."(p. 140)

Other risks from Bengio2025 (13)