Data acquisition restrictions
Laws and other regulations might limit the collection of certain types of data for specific AI use cases.
ENTITY
1 - Human
INTENT
2 - Unintentional
TIMING
1 - Pre-deployment
Risk ID
mit1275
Domain lineage
7. AI System Safety, Failures, & Limitations
7.3 > Lack of capability or robustness
Mitigation strategy
1. Implement a comprehensive AI governance and compliance framework to ensure adherence to emergent and established data privacy regulations (e.g., GDPR, CCPA, EU AI Act), focusing on defining the **lawful basis for data processing** and **purpose limitation** principles prior to initiating any data acquisition efforts. 2. Mandate the strict application of **data minimization** and **privacy-preserving techniques**—such as high-fidelity synthetic data generation, pseudonymization, or data masking—to reduce the collection and reliance on identifiable or sensitive data that is subject to the most stringent legal restrictions. 3. Conduct rigorous **pre-contractual due diligence** on all third-party data providers and model licensors to secure necessary usage rights and explicitly stipulate contractual **training data restrictions** that prohibit the use of identifiable personal or proprietary data for model training without explicit, documented approval, thereby mitigating legal and intellectual property vulnerabilities.