https://taxonomy.eticas.ai/risk/sensitive-information-leakage
Maturity: established
Personal or confidential/proprietary information present in training data, inference-time context, or connected systems, surfacing in model outputs through memorisation, context disclosure, cross-tenant contamination, or system-prompt extraction. Broadens the former pii-leakage (personal data only) to also cover organisational and commercial confidentiality (the former confidential-information-leakage, retired and absorbed here).
Also known as: PII leakage rate · Privacy leakage
System type: ADM and LLM systems
Lifecycle stages: In Processing, Post Processing
| Framework | Reference |
|---|---|
| EU AI Act (Regulation 2024/1689) | Article 15(5) — cybersecurity (confidentiality attacks) |
| AIUC-1 — AI Underwriting Company Standard | Prevent PII leakage |
| NIST AI 600-1 — Generative AI Risk Profile | Data Privacy (leakage clause) |
| Framework | Reference |
|---|---|
| MIT AI Risk Repository | Compromise of privacy by leaking or inferring sensitive information |
| W3C Data Privacy Vocabulary — AI Extension | Unauthorised Data Disclosure |
| AIR 2024 | Privacy → Unauthorized Privacy Violations × PII |
| IBM AI Risk Atlas | Output → Revealing personal information in output |
Source: HRA project taxonomy