AI risk domain 2

Privacy & Security

Subdomains

2.1 Compromise of privacy by obtaining, leaking or correctly inferring sensitive information
AI systems that memorize and leak sensitive personal data or infer private information about individuals without their consent. Unexpected or unauthorized sharing of data and information can compromise user expectation of privacy, assist identity theft, or loss of confidential intellectual property.
Profile and drilldown80 risk entries88 incidents
2.2 AI system security vulnerabilities and attacks
Vulnerabilities in AI systems, software development toolchains, and hardware that can be exploited, resulting in unauthorized access, data and privacy breaches, or system manipulation causing unsafe outputs or behavior.
Profile and drilldown112 risk entries24 incidents

Explore this domain in the MIT AI Risk Navigator

Recent incidents in this domain

  1. AI system security vulnerabilities...
  2. AI system security vulnerabilities...
  3. AI system security vulnerabilities...
  4. AI system security vulnerabilities...
  5. Compromise of privacy by obtaining...
  6. AI system security vulnerabilities...
  7. Compromise of privacy by obtaining...
  8. AI system security vulnerabilities...

Policies addressing related use cases

Editorial mapping by AIPolicyTracker

Use cases: biometricshealth

Colorado (United States) Act / statute Adopted Binding

Colorado AI Act

Colorado Senate Bill 24-205: Consumer Protections for Artificial Intelligence (Colorado AI Act)

The Colorado AI Act requires developers and deployers of high-risk AI systems to use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination. High-risk systems are those that make, or are a substantial factor in making, consequential decisions about education, employment, financial or lending services, essential government services, healthcare, housing, insurance or legal services. Deployers must run risk-management programmes and impact assessments, notify consumers, and explain adverse decisions; developers must document systems and disclose known risks.

Applies from 30 Jun 2026 Source-linked Official source
India Act / statute Partially applicable Binding

India DPDP Act

Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025

The DPDP Act is India's cross-sector personal-data law. It applies to digital personal data processed in India and to processing outside India connected with offering goods or services to people in India. It requires a lawful basis (consent or specified legitimate uses), notice, purpose limitation, data accuracy, security safeguards, breach notification to the Data Protection Board and affected individuals, and grants rights of access, correction, erasure and grievance redress. Significant Data Fiduciaries face extra duties such as impact assessments and audits. The Act does not mention AI specifically, but it governs the personal data used to train and operate AI systems.

Adopted 11 Aug 2023 Source-linked Official source
Nepal Act / statute In force Binding

Nepal Privacy Act 2075

Individual Privacy Act, 2075 (2018) — Nepal

The Individual Privacy Act 2075 gives effect to the constitutional right to privacy in Nepal. It regulates the collection, storage, processing, use and disclosure of personal information by public bodies and private entities, requires consent for collection and use of personal data subject to exceptions, restricts sensitive data, and provides remedies and penalties. It is the main binding law affecting AI systems that process personal data in Nepal. The Individual Privacy Regulation 2077 (2020) provides implementing rules.

In force 18 Sep 2018 Source-linked Official source
Italy Act / statute In force Binding

Law No. 132/2025 on artificial intelligence

Legge 23 settembre 2025, n. 132 – Disposizioni e deleghe al Governo in materia di intelligenza artificiale

Italy's framework AI law, published in the Official Gazette on 25 September 2025 and in force from 10 October 2025. It states principles (human-centric, transparent, safe AI; protection of fundamental rights), sets sector rules for healthcare (AI as support, not replacement, for clinical decisions), employment (information to workers, an AI-at-work observatory), intellectual professions (client disclosure), justice (judge decides; AI only for organisational support) and public administration, requires parental consent for children under 14, designates AgID and ACN as national authorities, delegates the government to align national law with the EU AI Act, and creates a criminal offence for unlawful dissemination of AI-generated or manipulated content with aggravating circumstances for other crimes committed with AI.

In force 10 Oct 2025 Source-linked · checked 11 Sep 2026 Official source
Denmark National strategy Adopted

National Strategy for Artificial Intelligence (2019)

National Strategy for Artificial Intelligence

Published in March 2019, the strategy sets a responsible foundation for AI (ethical principles, data ethics council, legal clarity), more and better data, strong competences and new knowledge, and increased investment, with priority sectors of health, energy and utilities, agriculture and transport, and a set of public-sector pilot projects.

Adopted 14 Mar 2019 Source-linked · checked 11 Sep 2026 Official source
Quebec (Canada) Act / statute In force Binding

Quebec Law 25 (automated decisions and biometrics)

Quebec Law 25 (S.Q. 2021, c. 25): provisions on decisions based exclusively on automated processing and biometric systems

Section 12.1 of the private-sector privacy act (as amended by Law 25, in force 22 September 2023) requires any enterprise that uses personal information to render a decision based exclusively on automated processing to inform the person no later than when the decision is made, and, on request, to tell them what personal information was used, the reasons and principal factors and parameters, and their right to have the information corrected, and to give them an opportunity to submit observations to a person who can review the decision. Biometric identification databases must be declared to the Commission d'accès à l'information 60 days before use, and privacy impact assessments are mandatory for projects involving personal information. Penalties reach CAD 25 million or 4% of worldwide turnover.

Applies from 22 Sep 2023 Source-linked · checked 11 Sep 2026 Official source
European Union Regulation Partially applicable Binding

EU AI Act

Regulation (EU) 2024/1689 — Artificial Intelligence Act

The EU AI Act is a binding regulation that sets rules for developing, placing on the market and using AI systems in the European Union. It bans a small set of practices considered unacceptable, imposes detailed requirements on "high-risk" AI systems used in areas such as employment, education, credit, essential services, law enforcement and safety-critical products, requires transparency for chatbots and synthetic content, and creates separate duties for providers of general-purpose AI models. Obligations apply in phases between 2025 and 2027.

Applies from 2 Aug 2026 Source-linked Official source
Texas (United States) Act / statute In force Binding

Texas Responsible AI Governance Act (TRAIGA)

Texas Responsible Artificial Intelligence Governance Act (HB 149, 89th Legislature)

Signed on 22 June 2025 and effective 1 January 2026, TRAIGA bans developing or deploying AI systems intended to manipulate people into self-harm or crime, government social scoring, biometric identification by government from public data without consent, intentional unlawful discrimination against protected classes, and production of child sexual abuse material or unlawful sexual deepfakes. State agencies and health-care providers must disclose AI interactions. It creates a 36-month regulatory sandbox administered by the Department of Information Resources, a Texas Artificial Intelligence Council, and gives the Attorney General exclusive enforcement with civil penalties after a 60-day cure period; disparate impact alone does not prove intent to discriminate.

Applies from 1 Jan 2026 Source-linked · checked 11 Sep 2026 Official source

UNESCO Recommendation on the Ethics of AI

UNESCO Recommendation on the Ethics of Artificial Intelligence (adopted by the General Conference, 23 November 2021)

The first global normative instrument on AI ethics. It sets values (human rights and dignity, environment and ecosystem flourishing, diversity and inclusiveness, peaceful and just societies) and principles (proportionality and do no harm, safety and security, fairness, sustainability, privacy, human oversight, transparency and explainability, responsibility, awareness and literacy, multi-stakeholder governance), and eleven policy action areas from ethical impact assessment and data policy to gender, education, health and the environment. UNESCO supports implementation with a Readiness Assessment Methodology (RAM) and an Ethical Impact Assessment tool used by dozens of countries.

Adopted 23 Nov 2021 Source-linked · checked 11 Sep 2026 Official source
Utah (United States) Act / statute In force Binding

Utah Artificial Intelligence Policy Act (SB 149)

Utah Artificial Intelligence Policy Act (SB 149, 2024, as amended by SB 226 and SB 332 in 2025)

Effective 1 May 2024, the Act requires a person using generative AI to interact with a consumer in a consumer transaction to disclose clearly that the consumer is interacting with AI when asked (as amended in 2025, when the interaction is high-risk or on request), and requires providers of regulated occupations (for example health and legal services) to disclose generative-AI use proactively. It states that using AI is no defence to consumer-protection violations, created the Office of Artificial Intelligence Policy and an AI learning laboratory allowing regulatory mitigation agreements, and originally sunset in 2025, extended to 2027.

Applies from 1 May 2024 Source-linked · checked 11 Sep 2026 Official source

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.