MIT AI Risk Repository · domain 2: Privacy & Security

2.1 Compromise of privacy by obtaining, leaking or correctly inferring sensitive information

AI systems that memorize and leak sensitive personal data or infer private information about individuals without their consent. Unexpected or unauthorized sharing of data and information can compromise user expectation of privacy, assist identity theft, or loss of confidential intellectual property.

Risk entries
80
Frameworks citing it
12
Recorded incidents
88
Incidents since 2020
64
Causal entity (risk entries)
Causal entity (risk entries) 46 0 AI: 46 AI 46 Human: 20 Human 20 Other: 11 Other 11 Not coded: 3 Not coded 3
Causal entity (risk entries)
LabelValue
AI46
Human20
Other11
Not coded3
Intent (risk entries)
Intent (risk entries) 42 0 Unintentional: 42 Unintentional 42 Other: 25 Other 25 Intentional: 10 Intentional 10 Not coded: 3 Not coded 3
Intent (risk entries)
LabelValue
Unintentional42
Other25
Intentional10
Not coded3
Timing (risk entries)
Timing (risk entries) 43 0 Post-deployment: 43 Post-deployment 43 Other: 24 Other 24 Pre-deployment: 10 Pre-deployment 10 Not coded: 3 Not coded 3
Timing (risk entries)
LabelValue
Post-deployment43
Other24
Pre-deployment10
Not coded3
Recorded incidents per yearIncident date; current year partial
Recorded incidents per year 19 0 2013: 1 2013 1 2014: 1 2014 1 2015: 3 2015 3 2016: 1 2016 1 2017: 6 2017 6 2018: 5 2018 5 2019: 5 2019 5 2020: 5 2020 5 2021: 5 2021 5 2022: 8 2022 8 2023: 9 2023 9 2024: 14 2024 14 2025: 19 2025 19 2026: 4 2026 4
Recorded incidents per year
LabelValue
20131
20141
20153
20161
20176
20185
20195
20205
20215
20228
20239
202414
202519
20264
Entries by levelRisk categories, subcategories and additional evidence coded to this subdomain
Entries by level 60 0 Risk Category: 20 Risk Category 20 Risk Sub-Category: 60 Risk Sub-Category 60
Entries by level
LabelValue
Risk Category20
Risk Sub-Category60
  • Risks to privacy

    "General- purpose AI models or systems can ‘leak’ information about individuals whose data was used in training. For future models trained on sensitive personal data like health or financial data, thi...

    International Scientific Report on the Safety of Advanced AI (Bengio2024) · AI · Unintentional · Post-deployment

  • Risks to privacy

    "General- purpose AI systems can cause or contribute to violations of user privacy. Violations can occur inadvertently during the training or usage of AI systems, for example through unauthorised proc...

    International AI Safety Report 2025 (Bengio2025) · AI · Unintentional · Other

  • Privacy Leakage

    "Privacy Leakage means the generated content includes sensitive personal information"

    Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems (Cui2024) · AI · Unintentional · Post-deployment

  • Privacy Leakage

    "The model is trained with personal data in the corpus and unintentionally exposing them during the conversation."

    Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems (Cui2024) · AI · Unintentional · Other

  • Private Training Data

    "As recent LLMs continue to incorporate licensed, created, and publicly available data sources in their corpora, the potential to mix private data in the training corpora is significantly increased. T...

    Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems (Cui2024) · Human · Unintentional · Pre-deployment

  • Memorization in LLMs

    "Memorization in LLMs refers to the capability to recover the training data with contextual prefixes. According to [88]–[90], given a PII entity x, which is memorized by a model F. Using a prompt p co...

    Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems (Cui2024) · AI · Unintentional · Pre-deployment

  • Association in LLMs

    "Association in LLMs refers to the capability to associate various pieces of information related to a person. According to [68], [86], given a pair of PII entities (xi , xj ), which is associated by a...

    Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems (Cui2024) · AI · Unintentional · Pre-deployment

  • Privacy and regulation violations

    "Some of the broken systems discussed above are also very invasive of people’s privacy, controlling, for instance, the length of someone’s last romantic relationship [51]. More recently, ChatGPT was b...

    Navigating the Landscape of AI Ethics and Responsibility (Cunha2023) · Human · Intentional · Post-deployment

  • Privacy and Data Leakage

    Large pre-trained models trained on internet texts might contain private information like phone numbers, email addresses, and residential addresses.

    Towards Safer Generative Language Models: A Survey on Safety Risks, Evaluations, and Improvements (Deng2023) · AI · Unintentional · Pre-deployment

  • Opaque Data Collection

    "When companies scrape personal information and use it to create generative AI tools, they undermine consumers' control of their personal information by using the information for a purpose for which t...

    Generating Harms - Generative AI's impact and paths forwards (EPIC2023) · Human · Intentional · Pre-deployment

  • Scraping to train data

    "When companies scrape personal information and use it to create generative AI tools, they undermine consumers’ control of their personal information by using the information for a purpose for which t...

    Generating Harms - Generative AI's impact and paths forwards (EPIC2023) · Human · Intentional · Pre-deployment

  • Generative AI User Data

    Many generative AI tools require users to log in for access, and many retain user information, including contact information, IP address, and all the inputs and outputs or “conversations” the users ar...

    Generating Harms - Generative AI's impact and paths forwards (EPIC2023) · Human · Unintentional · Post-deployment

  • Generative AI Outputs

    Generative AI tools may inadvertently share personal information about someone or someone’s business or may include an element of a person from a photo. Particularly, companies concerned about their t...

    Generating Harms - Generative AI's impact and paths forwards (EPIC2023) · AI · Unintentional · Post-deployment

  • Personal Loss and Identity Theft

    "These types of harm encompass threats to an individual’s personal identity, such as identity theft, privacy breaches, or personal defamation, which we term as “Harm to the Person.”"

    GenAI against humanity: nefarious applications of generative artificial intelligence and large language models (Ferrara2023) · Other · Other · Other

  • Adversarial AI: Data and Model Exfiltration Attacks

    "Other forms of abuse can include privacy attacks that allow adversaries to exfiltrate or gain knowledge of the private training data set or other valuable assets. For example, privacy attacks such as...

    The Ethics of Advanced AI Assistants (Gabriel2024) · Human · Intentional · Post-deployment

  • Privacy Harms

    "These harms relate to violations of an individual’s or group’s moral or legal right to privacy. Such harms may be exacerbated by assistants that influence users to disclose personal information or pr...

    The Ethics of Advanced AI Assistants (Gabriel2024) · AI · Other · Post-deployment

  • Private information leakage

    "First, because LLMs display immense modelling power, there is a risk that the model weights encode private information present in the training corpus. In particular, it is possible for LLMs to ‘memor...

    The Ethics of Advanced AI Assistants (Gabriel2024) · Other · Other · Other

  • Inference of private information

    "Finally, LLMs can in principle infer private information based on model inputs even if the relevant private information is not present in the training corpus (Weidinger et al., 2021). For example, an...

    The Ethics of Advanced AI Assistants (Gabriel2024) · AI · Unintentional · Post-deployment

  • Privacy

    "Privacy Acceptable responses may contain publicly available information about an individual. Unacceptable responses will contain sensitive, non-public personal information that could undermine someon...

    AILUMINATE: Introducing v1.0 of the AI Risk and Reliability Benchmark from MLCommons (Ghosh2024) · AI · Other · Post-deployment

  • Privacy protection

    "This group represents almost 14% of the articles and focuses on two primary issues related to privacy."

    What Ethics Can Say on Artificial Intelligence: Insights from a Systematic Literature Review (Giarmoleo2024) · Other · Other · Other

  • Impacts of AI (Privacy)

    -

    Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems (Gipiškis2024) · Not coded · Not coded · Not coded

  • Decision-making on inferred private data

    "Current GPAIs (LLMs and multimodal LLM-based models) have significant capability to infer correlations in text data. In some cases, they may be able to make highly accurate data inferences on users b...

    Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems (Gipiškis2024) · AI · Other · Post-deployment

  • Legal challenges

    "Since the release of ChatGPT, significant discourse has emerged regarding the unprecedented legal challenges posed by generative AI systems. These challenges primarily involve protecting privacy and...

    Regulating under Uncertainty: Governance Options for Generative AI (G'sell2024) · Other · Other · Other

  • Privacy and data collection concerns (collecting personal information or personally identifiable information)

    "Generative AI developers train their models with extensive datasets often gathered through online web scraping of websites that may include personal data or personally identifiable information (PII)....

    Regulating under Uncertainty: Governance Options for Generative AI (G'sell2024) · Human · Unintentional · Pre-deployment

  • Privacy and data collection concerns (data protection concerns)

    "The incorporation of personal data within training datasets raises numerous concerns. The primary issue is that personal data may be incorporated without the knowledge or consent of the individuals c...

    Regulating under Uncertainty: Governance Options for Generative AI (G'sell2024) · AI · Unintentional · Post-deployment