AI Security, Intellectual Property (IP) & Privacy Gaps – What is confidential to AI?

31 Oct. 2024 - - Total Reads 818

AI Security and IP

Why AI doesn’t know what’s confidential — and how to protect your business from exposure

AI models are not inherently secure. They’re not aware of what’s private, regulated, or commercially sensitive. When you pass confidential information into ChatGPT or other large language models, they don’t have built-in filters to protect your IP, redact private user data, or comply with privacy frameworks like GDPR or HIPAA. That’s your job — and in regulated industries, failing to do so can trigger serious consequences.

Why This Is a Problem

LLMs don’t understand security boundaries. If you give them sensitive content — a legal contract, internal strategy doc, or a patient file — they’ll happily analyse, summarise, and even remix that data. Worse, if you don’t properly clean the inputs and outputs, the model can:

  • Leak confidential info in its responses
  • Include identifying data when responding to unrelated prompts
  • Misclassify, hallucinate, or suggest actions that violate compliance rules

Does OpenAI Train on Your Data?

By default, yes — inputs into ChatGPT may be used to improve the model. This includes prompts and content submitted through the public web interface (chat.openai.com). However, API usage is opt-out by default — OpenAI states that API inputs are not used for training unless explicitly enabled.

Still, if your data is proprietary or sensitive, it’s safest to:

  • Assume all external model use is untrusted
  • Treat prompts as if you’re publishing to the internet

Mitigation Strategies

1. Redact and Mask Data Before Sending to the Model

Remove or replace identifiable fields before sending prompts;

user_prompt = “Customer John Smith at ACME Corp requested refund.”
safe_prompt = user_prompt.replace(“John Smith”, “[REDACTED_NAME]”).replace(“ACME Corp”, “[REDACTED_ORG]”)

Use token-based masking for more granular protection.

2. Hash Identifiable Fields (for reversible matching)

If you need to link back to original data later:

You can store this hash as a reference key — the model sees only anonymised input.

3. Use Internal LLMs or Isolated Environments

For highly sensitive work (IP, legal, R&D), consider:

  • Running LLMs in a private cloud or on-prem
  • Using open-source models like LLaMA or Mistral inside firewalled environments
  • Wrapping models with policy enforcement, logging, and audit tools

4. Filter and Post-Process AI Output

Even if input is safe, the model can still generate unsafe responses. Use regex filters, classification models, or human review to scrub outputs before they’re exposed to users.

When This Matters Most

  • Legal: Leaking case files or privileged communications
  • Healthcare: Exposing patient info, violating healthcare codes
  • Finance: Sharing transaction history, insider data
  • Tech: Revealing product roadmaps, code, or strategies

Final Thought

LLMs don’t protect your data — they process what you give them. That means security and privacy need to be enforced before and after the model, not just inside it. With smart redaction, structured pipelines, and enterprise-grade access control, AI becomes powerful and safe.

Need help deploying AI without risking your IP? AndMine can help you design secure, scalable AI systems that protect your data and reputation.

Michael Simonetti, BSc BE MTE
Posted by:

Post Reads: 818

Share this

Go on, see if you can challenge us on "AI Security, Intellectual Property (IP) & Privacy Gaps – What is confidential to AI?" - Part of our 183 services at AndMine. We are quick to respond but if you want to go direct, test us during office hours.

Add Your Comment

Trusted by

Magento Solution Specialist
Tek Ocean
High Street Armadale
Instant RockStar
Ego Pharmaceuticals
Ubertas Group
Amino Active
Peter Mac
Catholic Insurance
Fairfax Media
Plants
News
National Relay Services
Victorian Government
HGG 
Parker Lane
Telstra
Tomorrow Stars Basketball
iPrimus
Globird
Van Egmond Group
King Wood Mallesons
Sports Power
Maxine
Wild Rhino Shoes
Fit My Car
Grow Your Business
Federation University Australia
Think & Grow Rich Inc
Sunday Creek
itfe logo
kestrel logo
ISO Certified
Carlton Football Club
Kadac
Watches of Switzerland
Movember
Ebay
Brisbane Times
Scrum.org
Kay&Burton
Microsoft Certified Azure Fundamentals
Atlantic Group of Companies
Magento
Mecca Brands
The Burger Cheese
The Age
mas national logo
DUSA, Deakin University Student Association
Mamma Lucia
Loan Market
Boston Consulting Group
skillhire logo
Oakdale Meat Co
Natralus Australia
Bostik
Melrose Health
Melrose MCT
help logo
Paypal
Grainshaker
Gilchrist Connell
Launtel
liberal
White Suede
Taylor Rose
OJAY
Mark Alexander Design
Gilbert+Tobin
Melbourne Central
OpenAI
learning partners logo
PranaOn
Australian Physiotherapy Association
Matchbox Homewares
Bintani Australia
htn logo
Unsw Australia
Max’s
POSTER Magazine
Beaumont
MyAccount
Engineers Without Borders
Adobe Professional
Cronos Australia
aga logo
Etihad Stadium
Inferflora
Uber
Garmin
Craft CMS
Madman Entertainment
Bolle Safety
Coles
Royal Freemasons
Gadens
Toy World
Hanover
GooglePlay
nara logo
Palace Cinemas
Melbourne Sports and Aquatic Centre – MSAC
James Buyer Advocates
Jalna
RMIT University
CAN- Common Wealth Bank
McArthur Skincare
Ello
Positive Poster
Shell
SMH – The Sydney Morning Herald
ISO CERTIFIED 27001
131 Pizza
Associated Press
Tribe
Fast.co
University of South Australia
Australian Anthill
Celebrate Health
Chia
Oracle
Windsorsmith
Dinosaur Designs
French Tables
Novvi
One Shift
DeeWhy Market
Engine Swim
Toni&Guy
interact logo
The University Of Melbourne
WTFN
Smart Company
Macmillan Publishing
Corrs chambers westgarth
Bank of Cyprus
ctc logo
Thomson Geer
Florsheim Shoes
CCI
CB Richard Ellis
Bondi Sands
intojobs logo
Passage Foods
NextTech
ADP Payroll
Cooper Mills
Acquia Certified Site Builder Drupal
Moov Head Lice
Aqium Gel
Naturtint
GPT Group
Xavier
Grays Ecommerce
The Fortune Institute
Federation Square
MAP
Australian Government
National Museum of Australia
Rock Pool Group
ATT logo
Heat Holders
Green St Juice CO
SwinBurne University of Technology
Dial Before You Dig
Bigcommerce
Switzer Media+Publishing
Crumpler
Australian Organic Food CO
Castran Gilbert
Cell Therapies
Marshall White
Schiavello
Bulk Nutrients
Vendor Advocacy Australia
NGS Super
nextgenskills logo
Passage To India
Forbes
Jetstar
Tassal
work and training logo
Viktoria & Woods
Street Kitchen
VISSF
Drupal
BlackMores
Elucent
NMI Insurance
ACTUATE IP
Arc One
Eway
QV Skincare
intowork logo
21st Century Australia Party
OMS – Order Management System
The Royal Melbourne Hospital
Appstore
Arthur Galan
ABC
findstaff logo
Google
The Canberra Times
Melbourne Heart
TPP
Fresh Cheese Company
Rackspace
Cleanfit
SunSense Digital Agency
Focus On Furniture
Macpherson Kelley
AC/DC
Vitura Health
Hairhouse Warehouse
LBG Australia and New Zealand
Metricon
Rydges
Banki Haddock Fiora
Herbert Smith Freehills

Testimonials

Not only is Michael professional but he is also a great friend to have in your court. He is balanced in his advice, fair in his quotes and has the best twitter feed for all things tech - i highly recommend you follow him and also hire him! Clare Smith, GM – Brand & Marketing Communications at Sensis

More Testimonials
AndMine-Google-Partner-Signature