MIT AI Risk Repository · domain 2: Privacy & Security

2.1 Compromise of privacy by obtaining, leaking or correctly inferring sensitive information

AI systems that memorize and leak sensitive personal data or infer private information about individuals without their consent. Unexpected or unauthorized sharing of data and information can compromise user expectation of privacy, assist identity theft, or loss of confidential intellectual property.

Risk entries
80
Frameworks citing it
12
Recorded incidents
88
Incidents since 2020
64
Causal entity (risk entries)
Causal entity (risk entries) 46 0 AI: 46 AI 46 Human: 20 Human 20 Other: 11 Other 11 Not coded: 3 Not coded 3
Causal entity (risk entries)
LabelValue
AI46
Human20
Other11
Not coded3
Intent (risk entries)
Intent (risk entries) 42 0 Unintentional: 42 Unintentional 42 Other: 25 Other 25 Intentional: 10 Intentional 10 Not coded: 3 Not coded 3
Intent (risk entries)
LabelValue
Unintentional42
Other25
Intentional10
Not coded3
Timing (risk entries)
Timing (risk entries) 43 0 Post-deployment: 43 Post-deployment 43 Other: 24 Other 24 Pre-deployment: 10 Pre-deployment 10 Not coded: 3 Not coded 3
Timing (risk entries)
LabelValue
Post-deployment43
Other24
Pre-deployment10
Not coded3
Recorded incidents per yearIncident date; current year partial
Recorded incidents per year 19 0 2013: 1 2013 1 2014: 1 2014 1 2015: 3 2015 3 2016: 1 2016 1 2017: 6 2017 6 2018: 5 2018 5 2019: 5 2019 5 2020: 5 2020 5 2021: 5 2021 5 2022: 8 2022 8 2023: 9 2023 9 2024: 14 2024 14 2025: 19 2025 19 2026: 4 2026 4
Recorded incidents per year
LabelValue
20131
20141
20153
20161
20176
20185
20195
20205
20215
20228
20239
202414
202519
20264
Entries by levelRisk categories, subcategories and additional evidence coded to this subdomain
Entries by level 60 0 Risk Category: 20 Risk Category 20 Risk Sub-Category: 60 Risk Sub-Category 60
Entries by level
LabelValue
Risk Category20
Risk Sub-Category60
  • Privacy

    Users’ data, including location, personal information, and navigation trajectory, are considered as input for most data-driven machine learning methods

    A Survey of Artificial Intelligence Challenges: Analyzing the Definitions, Relationships, and Evolutions (Saghiri2022) · AI · Other · Pre-deployment

  • Harming users’ data privacy

    "Modern AI systems rely on large amounts of data. If this includes personal data about individuals, the risk of harming the privacy of persons arises."

    AI Hazard Management: A Framework for the Systematic Management of Root Causes for AI Risks (Schnitzer2024) · Other · Other · Other

  • Privacy violations

    Privacy violation occurs when algorithmic systems diminish privacy, such as enabling the undesirable flow of private information [180], instilling the feeling of being watched or surveilled [181], and...

    Sociotechnical Harms of Algorithmic Systems: Scoping a Taxonomy for Harm Reduction (Shelby2023) · AI · Other · Post-deployment

  • Privacy

    "The potential for the AI system to infringe upon individuals' rights to privacy, through the data it collects, how it processes that data, or the conclusions it draws."

    AI Risk Profiles: A Standards Proposal for Pre-Deployment AI Risk Disclosures (Sherman2023) · AI · Other · Other

  • Privacy and Data Protection

    "Examining the ways in which generative AI systems providers leverage user data is critical to evaluating its impact. Protecting personal information and personal and group privacy depends largely on...

    Evaluating the Social Impact of Generative AI Systems in Systems and Society (Solaiman2023) · Human · Other · Other

  • Leakage

    "The chatbot reveals sensitive or confidential information."

    Emerging Risks and Mitigations for Public Chatbots: LILAC v1 (Stanley2024) · AI · Unintentional · Other

  • Personal data

    Negative outcomes: "Violation of privacy [106, 516, 357], lawsuit against maker"

    Emerging Risks and Mitigations for Public Chatbots: LILAC v1 (Stanley2024) · AI · Unintentional · Other

  • Proprietary data

    "Access to sensitive company data [473]"

    Emerging Risks and Mitigations for Public Chatbots: LILAC v1 (Stanley2024) · AI · Unintentional · Other

  • Elicits private data

    Emerging Risks and Mitigations for Public Chatbots: LILAC v1 (Stanley2024) · AI · Other · Other

  • Privacy and Property

    "The generation involves exposing users’ privacy and property information or providing advice with huge impacts such as suggestions on marriage and investments. When handling this information, the mod...

    Safety Assessment of Chinese Large Language Models (Sun2023) · AI · Other · Post-deployment

  • Prompt Leaking

    "By analyzing the model’s output, attackers may extract parts of the systemprovided prompts and thus potentially obtain sensitive information regarding the system itself."

    Safety Assessment of Chinese Large Language Models (Sun2023) · Human · Intentional · Post-deployment

  • Privacy

    The risk of loss or harm from leakage of personal information via the ML system.

    The Risks of Machine Learning Systems (Tan2022) · AI · Unintentional · Post-deployment

  • Information Science Risks

    "These risks pertain to the misuse, misinterpretation, or leakage of data, which can lead to erroneous conclusions or the unintentional dissemination of sensitive information, such as private patient...

    Risks of AI Scientists: Prioritizing Safeguarding Over Autonomy (Tang2025) · Other · Other · Post-deployment

  • Risks from data (Risks of illegal collection and use of data)

    "The collection of AI training data and the interaction with users during service provision pose security risks, including collecting data without consent and improper use of data and personal informa...

    AI Safety Governance Framework (TC2602024) · Human · Other · Other

  • Risks from data (Risks of data leakage)

    "In AI research, development, and applications, issues such as improper data processing, unauthorized access, malicious attacks, and deceptive interactions can lead to data and personal information le...

    AI Safety Governance Framework (TC2602024) · Human · Other · Other

  • Cyberspace risks (Risks of information leakage due to improper usage)

    "Staff of government agencies and enterprises, if failing to use the AI service in a regulated and proper manner, may input internal data and industrial information into the AI model, leading to the l...

    AI Safety Governance Framework (TC2602024) · Human · Unintentional · Post-deployment

  • Data Protection/Privacy

    "Vulnerable channel by which personal information may be accessed. The user may want their personal data to be kept private."

    An Exploratory Diagnosis of Artificial Intelligence Risks for a Responsible Governance (Teixeira2022) · Human · Unintentional · Post-deployment

  • Information Hazards

    "Harms that arise from the language model leaking or inferring true sensitive information"

    Ethical and social risks of harm from language models (Weidinger2021) · AI · Unintentional · Post-deployment

  • Compromising privacy by leaking private infiormation

    "By providing true information about individuals’ personal characteristics, privacy violations may occur. This may stem from the model “remembering” private information present in training data (Carli...

    Ethical and social risks of harm from language models (Weidinger2021) · AI · Unintentional · Post-deployment

  • Compromising privacy by correctly inferring private information

    "Privacy violations may occur at the time of inference even without the individual’s private data being present in the training dataset. Similar to other statistical models, a LM may make correct infe...

    Ethical and social risks of harm from language models (Weidinger2021) · AI · Unintentional · Post-deployment

  • Risks from leaking or correctly inferring sensitive information

    "LMs may provide true, sensitive information that is present in the training data. This could render information accessible that would otherwise be inaccessible, for example, due to the user not havin...

    Ethical and social risks of harm from language models (Weidinger2021) · Other · Other · Post-deployment

  • Risk area 2: Information Hazards

    "LM predictions that convey true information may give rise to information hazards, whereby the dissemination of private or sensitive information can cause harm [27]. Information hazards can cause harm...

    Taxonomy of Risks posed by Language Models (Weidinger2022) · AI · Unintentional · Post-deployment

  • Compromising privacy by leaking sensitive information

    "A LM can “remember” and leak private data, if such information is present in training data, causing privacy violations [34]."

    Taxonomy of Risks posed by Language Models (Weidinger2022) · AI · Unintentional · Post-deployment

  • Compromising privacy or security by correctly inferring sensitive information

    Anticipated risk: "Privacy violations may occur at inference time even without an individual’s data being present in the training corpus. Insofar as LMs can be used to improve the accuracy of inferenc...

    Taxonomy of Risks posed by Language Models (Weidinger2022) · AI · Unintentional · Post-deployment

  • Information & Safety Harms

    "AI systems leaking, reproducing, generating or inferring sensitive, private, or hazardous information"

    Sociotechnical Safety Evaluation of Generative AI Systems (Weidinger2023) · AI · Unintentional · Post-deployment