MIT AI Risk Repository · domain 2: Privacy & Security

2.1 Compromise of privacy by obtaining, leaking or correctly inferring sensitive information

AI systems that memorize and leak sensitive personal data or infer private information about individuals without their consent. Unexpected or unauthorized sharing of data and information can compromise user expectation of privacy, assist identity theft, or loss of confidential intellectual property.

Risk entries
80
Frameworks citing it
12
Recorded incidents
88
Incidents since 2020
64
Causal entity (risk entries)
Causal entity (risk entries) 46 0 AI: 46 AI 46 Human: 20 Human 20 Other: 11 Other 11 Not coded: 3 Not coded 3
Causal entity (risk entries)
LabelValue
AI46
Human20
Other11
Not coded3
Intent (risk entries)
Intent (risk entries) 42 0 Unintentional: 42 Unintentional 42 Other: 25 Other 25 Intentional: 10 Intentional 10 Not coded: 3 Not coded 3
Intent (risk entries)
LabelValue
Unintentional42
Other25
Intentional10
Not coded3
Timing (risk entries)
Timing (risk entries) 43 0 Post-deployment: 43 Post-deployment 43 Other: 24 Other 24 Pre-deployment: 10 Pre-deployment 10 Not coded: 3 Not coded 3
Timing (risk entries)
LabelValue
Post-deployment43
Other24
Pre-deployment10
Not coded3
Recorded incidents per yearIncident date; current year partial
Recorded incidents per year 19 0 2013: 1 2013 1 2014: 1 2014 1 2015: 3 2015 3 2016: 1 2016 1 2017: 6 2017 6 2018: 5 2018 5 2019: 5 2019 5 2020: 5 2020 5 2021: 5 2021 5 2022: 8 2022 8 2023: 9 2023 9 2024: 14 2024 14 2025: 19 2025 19 2026: 4 2026 4
Recorded incidents per year
LabelValue
20131
20141
20153
20161
20176
20185
20195
20205
20215
20228
20239
202414
202519
20264
Entries by levelRisk categories, subcategories and additional evidence coded to this subdomain
Entries by level 60 0 Risk Category: 20 Risk Category 20 Risk Sub-Category: 60 Risk Sub-Category 60
Entries by level
LabelValue
Risk Category20
Risk Sub-Category60