READING ROOM ↗

Privacy in AI deployments

Collecting and using personal data creates questions about purpose, access and retention.

Last reviewed
Jurisdiction / scope
Global
Record date / period
Date not established
Assessment confidence
Not scored

Overview

Privacy risk depends on data practices throughout a system’s lifecycle.

Why it matters

People may have little visibility into how information about them is collected or used.

Current evidence

NIST’s GenAI Profile includes data privacy among its risk areas.

What we know

A risk category is not evidence that a specific product leaked data.

What we do not know

What information is retained, who can access it, and how can an affected person challenge its use?

Key uncertainties

Deployment-specific data flows and access controls need investigation.

Current assessment

Map data uses before drawing conclusions about an individual system.

Methodology

General risk framing; no unsupported breach or severity claim.

Related records.

Links provide context. Read the stated relationship; inclusion does not imply misconduct, endorsement or a legal obligation.

Incidents

Research

Sources.

  1. Federal Trade Commission · Primary source · Regulator complaint
    Published 2023-12-19 · Accessed 2026-10-07

  2. NIST · Primary source · Government technical report
    Published 2024-07 · Accessed 2026-10-07

    DOI: 10.6028/NIST.AI.600-1

Record history.

Review dates track editorial checks. Updates may reflect corrections or added context; they are not new incidents. Private draft revisions are omitted.

  1. · Revision 1

    Initial sourced historical collection. Review date describes this record, not the date of the event.

About PSYBORG · Contact and correction requests