MIT AI Risk Repository · domain 2: Privacy & Security
2.1 Compromise of privacy by obtaining, leaking or correctly inferring sensitive information
AI systems that memorize and leak sensitive personal data or infer private information about individuals without their consent. Unexpected or unauthorized sharing of data and information can compromise user expectation of privacy, assist identity theft, or loss of confidential intellectual property.
Risk entries
80
Frameworks citing it
12
Recorded incidents
88
Incidents since 2020
64
Causal entity (risk entries)
Causal entity (risk entries)
Label
Value
AI
46
Human
20
Other
11
Not coded
3
Intent (risk entries)
Intent (risk entries)
Label
Value
Unintentional
42
Other
25
Intentional
10
Not coded
3
Timing (risk entries)
Timing (risk entries)
Label
Value
Post-deployment
43
Other
24
Pre-deployment
10
Not coded
3
Recorded incidents per yearIncident date; current year partial
Recorded incidents per year
Label
Value
2013
1
2014
1
2015
3
2016
1
2017
6
2018
5
2019
5
2020
5
2021
5
2022
8
2023
9
2024
14
2025
19
2026
4
Entries by levelRisk categories, subcategories and additional evidence coded to this subdomain