AIBlindspot
← All case studies
DATDAT-002 — Data Privacy and Protection Failures

Generative AI Systems Train on Personal Data Without User Consent

4/5Sector: OtherGeography: GlobalStage: OperateIngested: —

Executive Summary

Generative AI models ingest rich personal data without notifying or obtaining consent from the individuals concerned, systematically excluding affected users from meaningful control. Boards face compounding regulatory exposure and reputational liability as consent failures scale across user populations.

Domain

Data Management

Blindspots in data quality, privacy, bias, lineage, lifecycle, and third-party data dependencies.

Source

MIT AI Risk Repository — A Closer Look at the Existing Risks of Generative AI: Mapping the Who, What, and How of Real-World Incidents (Li2025) ↗

https://airisk.mit.edu/

Could this happen in your organisation?

A Velinor AI Audit maps your active AI portfolio against the 50+ blindspots and benchmarks against documented sector failures like this one. A board-ready foresight document in 5 weeks.