Versatile AI Risk Assessment

AI threat cataloguePrivacy and Data LeakageProduction

Sensitive Information Disclosure

An AI system discloses confidential information without anyone intending it: trade secrets, personal data, credentials or internal documents surface in the model's answers.

As of: July 2026 · Catalogue version 2026.07.17.3 · 4 mitigations · 18 verified sources

Description

Language models memorise parts of their training data and can later reproduce them verbatim or slightly altered. Confidential content reaches the answers along several paths: through memorised training data, through connected knowledge sources such as document stores and databases, or through inputs from other users. The disclosure is triggered by normal use, by deliberately crafted questions, or by prompt injection, meaning smuggled-in instructions that bypass protective filters. A second path arises in everyday work: employees enter confidential material into external AI services whose operators store the inputs and may use them for further training.

Possible impact

Trade secrets and customer data end up in the wrong hands; where personal data is involved, GDPR notification duties, fines and claims by data subjects can follow. Disclosed credentials open the door to follow-up attacks. Trust and reputation also suffer when customers learn that their data appears in answers given to third parties.

Example

Employees paste internal source code and meeting notes into a public AI chatbot to work faster. The content now sits with the provider and can flow into future model versions. One such case at a major electronics group became publicly known.

Recommended mitigations (4)

Every mitigation states its control type, effect, implementation level and the reason for the classification.

Framework mappings

Verified locations in OWASP, NIST AI RMF, MITRE ATLAS, the EU AI Act and further frameworks. The mappings are taxonomic, not evidence of compliance.

OWASP LLM Top 10 LLM02:2025NIST AI RMF Section 2.10 · Section 2.4 · Section 2.9 · MEASURE 2.10 · NISTAML.032 · NISTAML.035 · NISTAML.038MITRE ATLAS AML.T0057EU AI Act Article 13(1), 13(3)(b)(ii), (iv), (v) · Article 55(1)(b)GDPR Article 25(1)–(2) · EDPB Opinion 28/2024, Section 3.2BSI R2 · R25BIML BIML-LLM inference:10 · BIML-LLM raw:5 · BIML78 inference:5

Verified references (18)

Every reference states the framework, the exact location and the publishing organisation.

Terms on this page

Glossary terms that occur in this entry. Every link leads to the full explanation.

More entries from the topic group Privacy and Data Leakage.

Assess this threat in your own system

The live demo contains all 52 threats of this catalogue, including the EU AI Act and GDPR assessment. The free single modules cover AI risk, the EU AI Act and GDPR. No sign-up; the assessment runs locally in your browser.

Cite this entry

For reports, policies or internal documents; the link leads directly to this entry.

“Sensitive Information Disclosure”. Versatile AI Risk Assessment, AI threat catalogue, as of July 2026.
https://www.versatile-ai-risk-assessment.com/en/wissensbasis/threats/sensitive-information-disclosure/

← Back to the full catalogue