AI data leakage

The most common AI incident is not an attack at all. It is somebody pasting something confidential into a tool nobody assessed.

A contract, a customer list, patient information, unreleased code. No system was breached. The data simply arrived somewhere with its own rules about how long it is kept, whether it trains future models and who inside that company can see it. It rarely feels like a decision at the time, which is why it keeps happening, and why the answer is usually giving people a sanctioned tool rather than telling them not to.

Checked against the primary source.

More on AI security