AI Security, Intellectual Property (IP) & Privacy Gaps – What is confidential to AI?

31 Oct. 2024 - - Total Reads 454

AI Security and IP

Why AI doesn’t know what’s confidential — and how to protect your business from exposure

AI models are not inherently secure. They’re not aware of what’s private, regulated, or commercially sensitive. When you pass confidential information into ChatGPT or other large language models, they don’t have built-in filters to protect your IP, redact private user data, or comply with privacy frameworks like GDPR or HIPAA. That’s your job — and in regulated industries, failing to do so can trigger serious consequences.

Why This Is a Problem

LLMs don’t understand security boundaries. If you give them sensitive content — a legal contract, internal strategy doc, or a patient file — they’ll happily analyse, summarise, and even remix that data. Worse, if you don’t properly clean the inputs and outputs, the model can:

  • Leak confidential info in its responses
  • Include identifying data when responding to unrelated prompts
  • Misclassify, hallucinate, or suggest actions that violate compliance rules

Does OpenAI Train on Your Data?

By default, yes — inputs into ChatGPT may be used to improve the model. This includes prompts and content submitted through the public web interface (chat.openai.com). However, API usage is opt-out by default — OpenAI states that API inputs are not used for training unless explicitly enabled.

Still, if your data is proprietary or sensitive, it’s safest to:

  • Assume all external model use is untrusted
  • Treat prompts as if you’re publishing to the internet

Mitigation Strategies

1. Redact and Mask Data Before Sending to the Model

Remove or replace identifiable fields before sending prompts;

user_prompt = “Customer John Smith at ACME Corp requested refund.”
safe_prompt = user_prompt.replace(“John Smith”, “[REDACTED_NAME]”).replace(“ACME Corp”, “[REDACTED_ORG]”)

Use token-based masking for more granular protection.

2. Hash Identifiable Fields (for reversible matching)

If you need to link back to original data later:

You can store this hash as a reference key — the model sees only anonymised input.

3. Use Internal LLMs or Isolated Environments

For highly sensitive work (IP, legal, R&D), consider:

  • Running LLMs in a private cloud or on-prem
  • Using open-source models like LLaMA or Mistral inside firewalled environments
  • Wrapping models with policy enforcement, logging, and audit tools

4. Filter and Post-Process AI Output

Even if input is safe, the model can still generate unsafe responses. Use regex filters, classification models, or human review to scrub outputs before they’re exposed to users.

When This Matters Most

  • Legal: Leaking case files or privileged communications
  • Healthcare: Exposing patient info, violating healthcare codes
  • Finance: Sharing transaction history, insider data
  • Tech: Revealing product roadmaps, code, or strategies

Final Thought

LLMs don’t protect your data — they process what you give them. That means security and privacy need to be enforced before and after the model, not just inside it. With smart redaction, structured pipelines, and enterprise-grade access control, AI becomes powerful and safe.

Need help deploying AI without risking your IP? AndMine can help you design secure, scalable AI systems that protect your data and reputation.

Michael Simonetti, BSc BE MTE
Posted by:

Post Reads: 454

Share this

Go on, see if you can challenge us on "AI Security, Intellectual Property (IP) & Privacy Gaps – What is confidential to AI?" - Part of our 183 services at AndMine. We are quick to respond but if you want to go direct, test us during office hours.

Add Your Comment

Trusted by

Wild Rhino Shoes
Liveoneday
131 Pizza
Taylor Rose
ADP Payroll
Jetstar
DUSA, Deakin University Student Association
skillhire logo
MyAccount
Rock Pool Group
Kadac
Melbourne Heart
King Wood Mallesons
Banki Haddock Fiora
Jalna
ATT logo
LBG Australia and New Zealand
Melbourne Central
QV Skincare
Fairfax Media
Oakdale Meat Co
The Canberra Times
Royal Freemasons
Celebrate Health
WTFN
Windsorsmith
Crumpler
Macmillan Publishing
interact logo
Gadens
Bondi Sands
Garmin
Craft CMS
HGG 
Magento Solution Specialist
Fit My Car
Adobe Professional
National Museum of Australia
Sports Power
TPP
Macpherson Kelley
The University Of Melbourne
One Shift
Florsheim Shoes
Mamma Lucia
Positive Poster
Federation Square
The Age
Australian Physiotherapy Association
Magento
findstaff logo
Dinosaur Designs
High Street Armadale
Melbourne Sports and Aquatic Centre – MSAC
Launtel
The Burger Cheese
SwinBurne University of Technology
Switzer Media+Publishing
CAN- Common Wealth Bank
Toni&Guy
Smart Company
Natralus Australia
Beaumont
Think & Grow Rich Inc
Cell Therapies
ABC
Shell
Mark Alexander Design
Matchbox Homewares
Bintani Australia
PranaOn
Cronos Australia
Gilbert+Tobin
Associated Press
Heat Holders
help logo
CCI
SMH – The Sydney Morning Herald
Grainshaker
Max’s
Maxine
learning partners logo
Coles
University of South Australia
Amino Active
Loan Market
Drupal
Passage To India
Grays Ecommerce
The Fortune Institute
Ego Pharmaceuticals
Bolle Safety
Australian Anthill
Telstra
OpenAI
nara logo
intowork logo
Chia
Globird
21st Century Australia Party
Australian Government
Rydges
Atlantic Group of Companies
Eway
Herbert Smith Freehills
aga logo
Bigcommerce
DeeWhy Market
Schiavello
Microsoft Certified Azure Fundamentals
kestrel logo
Green St Juice CO
Watches of Switzerland
Cleanfit
Engine Swim
French Tables
News
Kay&Burton
Movember
Engineers Without Borders
Bostik
GPT Group
ISO CERTIFIED 27001
Boston Consulting Group
Catholic Insurance
Palace Cinemas
Etihad Stadium
Marshall White
Tek Ocean
Moov Head Lice
Carlton Football Club
Sunday Creek
ISO Certified
Melrose Health
Tribe
Google
OJAY
CB Richard Ellis
BlackMores
NextTech
Aqium Gel
Unsw Australia
intojobs logo
Tomorrow Stars Basketball
Paypal
ctc logo
Fresh Cheese Company
Ebay
Tassal
Acquia Certified Site Builder Drupal
htn logo
NMI Insurance
Xavier
Melrose MCT
Fast.co
Toy World
McArthur Skincare
SunSense Digital Agency
Vitura Health
Grow Your Business
Brisbane Times
Bulk Nutrients
Mecca Brands
nextgenskills logo
mas national logo
Parker Lane
Ello
Federation University Australia
Madman Entertainment
Forbes
Van Egmond Group
Castran Gilbert
Ubertas Group
Cooper Mills
Scrum.org
Passage Foods
VISSF
GooglePlay
Arc One
Hairhouse Warehouse
Metricon
Focus On Furniture
Australian Organic Food CO
Peter Mac
Oracle
liberal
RMIT University
White Suede
Viktoria & Woods
Elucent
Uber
The Royal Melbourne Hospital
NGS Super
Appstore
Arthur Galan
James Buyer Advocates
Victorian Government
Hanover
Novvi
Inferflora
iPrimus
Dial Before You Dig
work and training logo
AC/DC
Bank of Cyprus
MAP
ACTUATE IP
Thomson Geer
Naturtint
Instant RockStar
OMS – Order Management System
POSTER Magazine
Street Kitchen
Plants
Vendor Advocacy Australia
itfe logo
National Relay Services
Rackspace

Testimonials

Metricon recently worked with AndMine on a major online brand promotion. We were impressed with AndMine’s thinking from concept stage through to campaign execution. We would not hesitate to brief AndMine again on future projects. Yvonne Abood, Marketing Manager, Metricon Homes

More Testimonials
AndMine-Google-Partner-Signature