Record summary
A quick snapshot of what this page covers.
Risk profile
How this risk is described and categorized.
"General- purpose AI systems can cause or contribute to violations of user privacy. Violations can occur inadvertently during the training or usage of AI systems, for example through unauthorised processing of personal data or leaking health records used in training. But violations can also happen deliberately through the use of general- purpose AI by malicious actors; for example, if they use AI to infer private facts or violate security."
Suggested mitigations
Defenses that may help with related attacks.
Restrict Number of AI Model Queries
Control Access to AI Models and Data in Production
AI Telemetry Logging
Privileged AI Agent Permissions Configuration
Single-User AI Agent Permissions Configuration
AI Agent Tools Permissions Configuration
Human In-the-Loop for AI Agent Actions
Restrict AI Agent Tool Invocation on Untrusted Data
Segmentation of AI Agent Components
Input and Output Validation for AI Agent Components
Restrict Library Loading
Verify AI Artifacts
Vulnerability Scanning
User Training
AI Bill of Materials
Control Access to AI Models and Data at Rest
Sanitize Training Data
Maintain AI Dataset Provenance
Source
Research source for this risk, when available.
Included resource
International AI Safety Report 2025
Original source
MIT AI Risk Repository
Open the public repository used for AI risk records and taxonomy fields.
