BackSecondary use
Secondary use
Risk Domain
AI systems that memorize and leak sensitive personal data or infer private information about individuals without their consent. Unexpected or unauthorized sharing of data and information can compromise user expectation of privacy, assist identity theft, or cause loss of confidential intellectual property.
"The use of personal data collected for one purpose for a diferent purpose without end-user consent; AI exacerbates secondary use risks by creating new AI capabilities with collected personal data, and (re)creating models from a public dataset."
Entity— Who or what caused the harm
Intent— Whether the harm was intentional or accidental
Timing— Whether the risk is pre- or post-deployment
Other risks from Li et al. (2025) (40)
Autonomy
5.2 Loss of human agency and autonomyOtherOtherOther
Autonomy > Impersonation / identity theft
4.3 Fraud, scams, and targeted manipulationHumanIntentionalPost-deployment
Misinformation Harms
3.1 False or misleading informationAI systemOtherPost-deployment
Representation and Toxicity
1.0 Discrimination & ToxicityAI systemUnintentionalPost-deployment
IP / copyright / personality / rights loss
4.3 Fraud, scams, and targeted manipulationHumanIntentionalPost-deployment
Autonomy / agency loss
5.2 Loss of human agency and autonomyOtherOtherOther