DATDAT-002 — Data Privacy and Protection Failures
AI Model and Training Data Exfiltration via Adversarial API Attacks
4/5Sector: OtherGeography: GlobalStage: OperateIngested: —
Executive Summary
Adversaries can exploit public-facing model APIs to extract private training data, including sensitive medical records, and steal proprietary model architecture through membership inference and model distillation attacks. Without targeted mitigations, organisations face simultaneous breaches of data protection law and loss of core AI intellectual property.
Domain
Data Management
Blindspots in data quality, privacy, bias, lineage, lifecycle, and third-party data dependencies.
Source
MIT AI Risk Repository — The Ethics of Advanced AI Assistants (Gabriel2024) ↗https://airisk.mit.edu/
Could this happen in your organisation?
A Velinor AI Audit maps your active AI portfolio against the 50+ blindspots and benchmarks against documented sector failures like this one. A board-ready foresight document in 5 weeks.