AI Security, Intellectual Property (IP) & Privacy Gaps – What is confidential to AI?

31 Oct. 2024 - - Total Reads 766

AI Security and IP

Why AI doesn’t know what’s confidential — and how to protect your business from exposure

AI models are not inherently secure. They’re not aware of what’s private, regulated, or commercially sensitive. When you pass confidential information into ChatGPT or other large language models, they don’t have built-in filters to protect your IP, redact private user data, or comply with privacy frameworks like GDPR or HIPAA. That’s your job — and in regulated industries, failing to do so can trigger serious consequences.

Why This Is a Problem

LLMs don’t understand security boundaries. If you give them sensitive content — a legal contract, internal strategy doc, or a patient file — they’ll happily analyse, summarise, and even remix that data. Worse, if you don’t properly clean the inputs and outputs, the model can:

  • Leak confidential info in its responses
  • Include identifying data when responding to unrelated prompts
  • Misclassify, hallucinate, or suggest actions that violate compliance rules

Does OpenAI Train on Your Data?

By default, yes — inputs into ChatGPT may be used to improve the model. This includes prompts and content submitted through the public web interface (chat.openai.com). However, API usage is opt-out by default — OpenAI states that API inputs are not used for training unless explicitly enabled.

Still, if your data is proprietary or sensitive, it’s safest to:

  • Assume all external model use is untrusted
  • Treat prompts as if you’re publishing to the internet

Mitigation Strategies

1. Redact and Mask Data Before Sending to the Model

Remove or replace identifiable fields before sending prompts;

user_prompt = “Customer John Smith at ACME Corp requested refund.”
safe_prompt = user_prompt.replace(“John Smith”, “[REDACTED_NAME]”).replace(“ACME Corp”, “[REDACTED_ORG]”)

Use token-based masking for more granular protection.

2. Hash Identifiable Fields (for reversible matching)

If you need to link back to original data later:

You can store this hash as a reference key — the model sees only anonymised input.

3. Use Internal LLMs or Isolated Environments

For highly sensitive work (IP, legal, R&D), consider:

  • Running LLMs in a private cloud or on-prem
  • Using open-source models like LLaMA or Mistral inside firewalled environments
  • Wrapping models with policy enforcement, logging, and audit tools

4. Filter and Post-Process AI Output

Even if input is safe, the model can still generate unsafe responses. Use regex filters, classification models, or human review to scrub outputs before they’re exposed to users.

When This Matters Most

  • Legal: Leaking case files or privileged communications
  • Healthcare: Exposing patient info, violating healthcare codes
  • Finance: Sharing transaction history, insider data
  • Tech: Revealing product roadmaps, code, or strategies

Final Thought

LLMs don’t protect your data — they process what you give them. That means security and privacy need to be enforced before and after the model, not just inside it. With smart redaction, structured pipelines, and enterprise-grade access control, AI becomes powerful and safe.

Need help deploying AI without risking your IP? AndMine can help you design secure, scalable AI systems that protect your data and reputation.

Michael Simonetti, BSc BE MTE
Posted by:

Post Reads: 766

Share this

Go on, see if you can challenge us on "AI Security, Intellectual Property (IP) & Privacy Gaps – What is confidential to AI?" - Part of our 183 services at AndMine. We are quick to respond but if you want to go direct, test us during office hours.

Add Your Comment

Trusted by

OMS – Order Management System
Adobe Professional
NGS Super
nextgenskills logo
Arthur Galan
Rackspace
ISO CERTIFIED 27001
Aqium Gel
Cronos Australia
McArthur Skincare
SunSense Digital Agency
Inferflora
One Shift
Herbert Smith Freehills
Dinosaur Designs
RMIT University
Ego Pharmaceuticals
Bank of Cyprus
Florsheim Shoes
Celebrate Health
Launtel
ABC
iPrimus
Scrum.org
Green St Juice CO
BlackMores
TPP
CB Richard Ellis
Vendor Advocacy Australia
Royal Freemasons
GPT Group
findstaff logo
Novvi
Oakdale Meat Co
Crumpler
Coles
Focus On Furniture
Magento
Castran Gilbert
National Relay Services
Federation Square
liberal
James Buyer Advocates
Fit My Car
The University Of Melbourne
Marshall White
ADP Payroll
Gadens
Jalna
Amino Active
Watches of Switzerland
21st Century Australia Party
Tek Ocean
Schiavello
DeeWhy Market
Uber
Van Egmond Group
Sunday Creek
Switzer Media+Publishing
ISO Certified
University of South Australia
WTFN
Bondi Sands
Palace Cinemas
Banki Haddock Fiora
Wild Rhino Shoes
Passage To India
Ebay
CCI
AC/DC
White Suede
National Museum of Australia
Melbourne Sports and Aquatic Centre – MSAC
Loan Market
Xavier
Bintani Australia
Sports Power
htn logo
Viktoria & Woods
Mark Alexander Design
French Tables
Melbourne Central
OJAY
MAP
The Royal Melbourne Hospital
CAN- Common Wealth Bank
Rock Pool Group
Bolle Safety
Shell
Globird
ATT logo
131 Pizza
Unsw Australia
Bigcommerce
mas national logo
intowork logo
Tomorrow Stars Basketball
Macmillan Publishing
Arc One
Eway
Beaumont
nara logo
HGG 
News
Fairfax Media
Street Kitchen
The Fortune Institute
Kay&Burton
Gilbert+Tobin
High Street Armadale
Grow Your Business
Cell Therapies
Melrose MCT
Fast.co
SwinBurne University of Technology
Instant RockStar
Atlantic Group of Companies
Maxine
Thomson Geer
Telstra
learning partners logo
Associated Press
Metricon
Think & Grow Rich Inc
Australian Physiotherapy Association
Federation University Australia
Melbourne Heart
work and training logo
Google
Grainshaker
The Age
LBG Australia and New Zealand
Melrose Health
PranaOn
DUSA, Deakin University Student Association
Smart Company
Ello
Matchbox Homewares
Acquia Certified Site Builder Drupal
intojobs logo
Garmin
NMI Insurance
QV Skincare
Movember
Catholic Insurance
Windsorsmith
Paypal
Dial Before You Dig
Corrs chambers westgarth
interact logo
MyAccount
SMH – The Sydney Morning Herald
Moov Head Lice
Boston Consulting Group
The Canberra Times
Etihad Stadium
Plants
help logo
Elucent
King Wood Mallesons
ctc logo
Australian Organic Food CO
Craft CMS
Hairhouse Warehouse
Oracle
kestrel logo
Forbes
Kadac
itfe logo
Brisbane Times
VISSF
aga logo
Engineers Without Borders
Rydges
Engine Swim
Vitura Health
Bostik
Bulk Nutrients
Australian Government
skillhire logo
Gilchrist Connell
Chia
Tassal
NextTech
Ubertas Group
Appstore
Heat Holders
Magento Solution Specialist
Victorian Government
Microsoft Certified Azure Fundamentals
Toni&Guy
POSTER Magazine
Peter Mac
Max’s
Grays Ecommerce
Cooper Mills
Passage Foods
Mecca Brands
Carlton Football Club
The Burger Cheese
Fresh Cheese Company
Toy World
Jetstar
Mamma Lucia
Tribe
Positive Poster
Hanover
OpenAI
Taylor Rose
Natralus Australia
Cleanfit
Naturtint
Drupal
Macpherson Kelley
Parker Lane
Madman Entertainment
ACTUATE IP
Australian Anthill
GooglePlay

Testimonials

The &Mine team is great to work with and went beyond the brief to deliver a family violence website which was both engaging and easy to use. The team is collaborative, understand the constraints and sensitivities of a government environment and work alongside you to develop creative and practical solutions and ideas. Stakeholders have only had positive feedback about the website including with comments such as the best government website I have seen. Christine Panayotou, Director Communications, Family Safety Victoria

More Testimonials
AndMine-Google-Partner-Signature