AI Security, Intellectual Property (IP) & Privacy Gaps – What is confidential to AI?

31 Oct. 2024 - - Total Reads 545

AI Security and IP

Why AI doesn’t know what’s confidential — and how to protect your business from exposure

AI models are not inherently secure. They’re not aware of what’s private, regulated, or commercially sensitive. When you pass confidential information into ChatGPT or other large language models, they don’t have built-in filters to protect your IP, redact private user data, or comply with privacy frameworks like GDPR or HIPAA. That’s your job — and in regulated industries, failing to do so can trigger serious consequences.

Why This Is a Problem

LLMs don’t understand security boundaries. If you give them sensitive content — a legal contract, internal strategy doc, or a patient file — they’ll happily analyse, summarise, and even remix that data. Worse, if you don’t properly clean the inputs and outputs, the model can:

  • Leak confidential info in its responses
  • Include identifying data when responding to unrelated prompts
  • Misclassify, hallucinate, or suggest actions that violate compliance rules

Does OpenAI Train on Your Data?

By default, yes — inputs into ChatGPT may be used to improve the model. This includes prompts and content submitted through the public web interface (chat.openai.com). However, API usage is opt-out by default — OpenAI states that API inputs are not used for training unless explicitly enabled.

Still, if your data is proprietary or sensitive, it’s safest to:

  • Assume all external model use is untrusted
  • Treat prompts as if you’re publishing to the internet

Mitigation Strategies

1. Redact and Mask Data Before Sending to the Model

Remove or replace identifiable fields before sending prompts;

user_prompt = “Customer John Smith at ACME Corp requested refund.”
safe_prompt = user_prompt.replace(“John Smith”, “[REDACTED_NAME]”).replace(“ACME Corp”, “[REDACTED_ORG]”)

Use token-based masking for more granular protection.

2. Hash Identifiable Fields (for reversible matching)

If you need to link back to original data later:

You can store this hash as a reference key — the model sees only anonymised input.

3. Use Internal LLMs or Isolated Environments

For highly sensitive work (IP, legal, R&D), consider:

  • Running LLMs in a private cloud or on-prem
  • Using open-source models like LLaMA or Mistral inside firewalled environments
  • Wrapping models with policy enforcement, logging, and audit tools

4. Filter and Post-Process AI Output

Even if input is safe, the model can still generate unsafe responses. Use regex filters, classification models, or human review to scrub outputs before they’re exposed to users.

When This Matters Most

  • Legal: Leaking case files or privileged communications
  • Healthcare: Exposing patient info, violating healthcare codes
  • Finance: Sharing transaction history, insider data
  • Tech: Revealing product roadmaps, code, or strategies

Final Thought

LLMs don’t protect your data — they process what you give them. That means security and privacy need to be enforced before and after the model, not just inside it. With smart redaction, structured pipelines, and enterprise-grade access control, AI becomes powerful and safe.

Need help deploying AI without risking your IP? AndMine can help you design secure, scalable AI systems that protect your data and reputation.

Michael Simonetti, BSc BE MTE
Posted by:

Post Reads: 545

Share this

Go on, see if you can challenge us on "AI Security, Intellectual Property (IP) & Privacy Gaps – What is confidential to AI?" - Part of our 183 services at AndMine. We are quick to respond but if you want to go direct, test us during office hours.

Add Your Comment

Trusted by

Gilbert+Tobin
Catholic Insurance
Fresh Cheese Company
Movember
131 Pizza
NMI Insurance
Taylor Rose
RMIT University
Globird
Arc One
Australian Organic Food CO
ABC
Oakdale Meat Co
Naturtint
The Burger Cheese
iPrimus
ACTUATE IP
Uber
htn logo
Hanover
White Suede
Launtel
One Shift
Matchbox Homewares
NextTech
Moov Head Lice
SwinBurne University of Technology
Microsoft Certified Azure Fundamentals
Engineers Without Borders
Mamma Lucia
Heat Holders
Tribe
Adobe Professional
Kadac
OMS – Order Management System
HGG 
Dial Before You Dig
Smart Company
Herbert Smith Freehills
Bondi Sands
help logo
Maxine
Celebrate Health
Van Egmond Group
Focus On Furniture
Atlantic Group of Companies
skillhire logo
Metricon
Melrose MCT
DeeWhy Market
Toni&Guy
intowork logo
CB Richard Ellis
Positive Poster
Fast.co
Schiavello
findstaff logo
intojobs logo
Drupal
Ego Pharmaceuticals
Magento
News
ATT logo
Chia
Acquia Certified Site Builder Drupal
Inferflora
CCI
Grow Your Business
Paypal
Melbourne Central
GooglePlay
The Royal Melbourne Hospital
The Age
Fairfax Media
Associated Press
Rackspace
interact logo
Grays Ecommerce
French Tables
SMH – The Sydney Morning Herald
ADP Payroll
NGS Super
Arthur Galan
WTFN
Australian Physiotherapy Association
Natralus Australia
Ebay
liberal
Carlton Football Club
Bank of Cyprus
Loan Market
Castran Gilbert
Xavier
Garmin
Bintani Australia
Switzer Media+Publishing
Etihad Stadium
Forbes
The Fortune Institute
mas national logo
ISO Certified
Coles
Telstra
Ello
Royal Freemasons
learning partners logo
Aqium Gel
Cleanfit
Sunday Creek
Instant RockStar
QV Skincare
Bostik
Passage Foods
Australian Government
Toy World
aga logo
Viktoria & Woods
Google
Bolle Safety
Unsw Australia
Marshall White
Grainshaker
Crumpler
PranaOn
MyAccount
ctc logo
Melrose Health
Ubertas Group
Jetstar
Federation University Australia
Federation Square
The University Of Melbourne
Elucent
Dinosaur Designs
Macmillan Publishing
Plants
Windsorsmith
National Relay Services
Engine Swim
GPT Group
LBG Australia and New Zealand
Think & Grow Rich Inc
Hairhouse Warehouse
James Buyer Advocates
Rock Pool Group
POSTER Magazine
Brisbane Times
Vendor Advocacy Australia
Passage To India
Rydges
Florsheim Shoes
Thomson Geer
Cell Therapies
Wild Rhino Shoes
Sports Power
Scrum.org
Gadens
Mark Alexander Design
nara logo
Street Kitchen
SunSense Digital Agency
Magento Solution Specialist
21st Century Australia Party
Tassal
Banki Haddock Fiora
OJAY
TPP
Boston Consulting Group
DUSA, Deakin University Student Association
High Street Armadale
Vitura Health
CAN- Common Wealth Bank
nextgenskills logo
National Museum of Australia
Peter Mac
MAP
King Wood Mallesons
McArthur Skincare
Fit My Car
work and training logo
Mecca Brands
Shell
Victorian Government
Parker Lane
Cooper Mills
Bulk Nutrients
Jalna
Watches of Switzerland
Green St Juice CO
Kay&Burton
Madman Entertainment
Bigcommerce
AC/DC
Melbourne Sports and Aquatic Centre – MSAC
Tomorrow Stars Basketball
itfe logo
Macpherson Kelley
Novvi
Appstore
Amino Active
Tek Ocean
Palace Cinemas
Beaumont
BlackMores
Cronos Australia
Melbourne Heart
Max’s
VISSF
Craft CMS
OpenAI
kestrel logo
ISO CERTIFIED 27001
The Canberra Times
Oracle
Eway
University of South Australia
Australian Anthill

Testimonials

Just a quick note to say a big thanks and well done for doing what you said you would - building us a world class Health Food web site.  It looks great! We will find a way to properly thank your team for their hard work and terrific results. Russell, CEO, Melrose Health

More Testimonials
AndMine-Google-Partner-Signature