SECSEC-002 — Data Poisoning Attack Risks
AI Systems Sending Unauthorised Outbound Data Due to Inadequate Network Controls
5/5Sector: OtherGeography: GlobalStage: OperateIngested: —
Executive Summary
Network-connected AI systems can exfiltrate confidential data or execute unauthorised transactions when least-privilege controls and communication whitelists are absent. Boards face liability for data protection breaches and operational losses arising from unconstrained AI network access.
Domain
Security & Privacy
Blindspots in model security, data poisoning, privacy leakage, infrastructure, model theft, and incident response.
Source
MIT AI Risk Repository — Risk Sources and Risk Management Measures in Support of Standards for General-Purpose AI Systems (Gipiškis2024) ↗https://airisk.mit.edu/
Could this happen in your organisation?
A Velinor AI Audit maps your active AI portfolio against the 50+ blindspots and benchmarks against documented sector failures like this one. A board-ready foresight document in 5 weeks.