DATDAT-002 — Data Privacy and Protection Failures
Generative AI Tools Harvesting User Data to Retrain Models Without Clear Consent
3/5Sector: OtherGeography: GlobalStage: OperateIngested: —
Executive Summary
Generative AI platforms routinely retain user inputs, outputs, and identifiers, using them to retrain models without meaningful informed consent. Organisations deploying such tools face regulatory exposure under data protection law and reputational liability for undisclosed data practices.
Domain
Data Management
Blindspots in data quality, privacy, bias, lineage, lifecycle, and third-party data dependencies.
Source
MIT AI Risk Repository — Generating Harms - Generative AI's impact and paths forwards (EPIC2023) ↗https://airisk.mit.edu/
Could this happen in your organisation?
A Velinor AI Audit maps your active AI portfolio against the 50+ blindspots and benchmarks against documented sector failures like this one. A board-ready foresight document in 5 weeks.