Back to the MIT repository
2. Privacy & Security2 - Post-deployment

Privacy loss

Privacy loss - Unwarranted exposure of an individual’s private life or personal data through cyberattacks, doxxing, etc.

Source: MIT AI Risk Repositorymit966

ENTITY

1 - Human

INTENT

1 - Intentional

TIMING

2 - Post-deployment

Risk ID

mit966

Domain lineage

2. Privacy & Security

186 mapped risks

2.2 > AI system security vulnerabilities and attacks

Mitigation strategy

1. Implement robust encryption for all sensitive data, both at rest and in transit, coupled with stringent Role-Based Access Controls (RBAC) to enforce the principle of least privilege across all AI system components. 2. Establish continuous, real-time monitoring and threat detection systems across the AI pipeline and associated data repositories, complemented by regular security audits and penetration testing to proactively identify and remediate vulnerabilities. 3. Develop and enforce a comprehensive data governance framework that includes mandatory employee security awareness training on cyber threats (e.g., phishing and social engineering) and ensure strict adherence to all relevant data protection regulations (e.g., GDPR).