Skip to main content
BackExposing personal information
Home/Risks/IBM2025/Exposing personal information

Exposing personal information

Sub-category
Risk Domain

AI systems that memorize and leak sensitive personal data or infer private information about individuals without their consent. Unexpected or unauthorized sharing of data and information can compromise user expectation of privacy, assist identity theft, or cause loss of confidential intellectual property.

"When personal identifiable information (PII) or sensitive personal information (SPI) are used in training data, fine-tuning data, or as part of the prompt, models might reveal that data in the generated output. Revealing personal information is a type of data leakage."

Supporting Evidence (1)

1.
"Sharing people’s PI impacts their rights and make them more vulnerable."

Other risks from IBM2025 (63)