AI Security, Intellectual Property (IP) & Privacy Gaps – What is confidential to AI?

31 Oct. 2024 - - Total Reads 767

AI Security and IP

Why AI doesn’t know what’s confidential — and how to protect your business from exposure

AI models are not inherently secure. They’re not aware of what’s private, regulated, or commercially sensitive. When you pass confidential information into ChatGPT or other large language models, they don’t have built-in filters to protect your IP, redact private user data, or comply with privacy frameworks like GDPR or HIPAA. That’s your job — and in regulated industries, failing to do so can trigger serious consequences.

Why This Is a Problem

LLMs don’t understand security boundaries. If you give them sensitive content — a legal contract, internal strategy doc, or a patient file — they’ll happily analyse, summarise, and even remix that data. Worse, if you don’t properly clean the inputs and outputs, the model can:

  • Leak confidential info in its responses
  • Include identifying data when responding to unrelated prompts
  • Misclassify, hallucinate, or suggest actions that violate compliance rules

Does OpenAI Train on Your Data?

By default, yes — inputs into ChatGPT may be used to improve the model. This includes prompts and content submitted through the public web interface (chat.openai.com). However, API usage is opt-out by default — OpenAI states that API inputs are not used for training unless explicitly enabled.

Still, if your data is proprietary or sensitive, it’s safest to:

  • Assume all external model use is untrusted
  • Treat prompts as if you’re publishing to the internet

Mitigation Strategies

1. Redact and Mask Data Before Sending to the Model

Remove or replace identifiable fields before sending prompts;

user_prompt = “Customer John Smith at ACME Corp requested refund.”
safe_prompt = user_prompt.replace(“John Smith”, “[REDACTED_NAME]”).replace(“ACME Corp”, “[REDACTED_ORG]”)

Use token-based masking for more granular protection.

2. Hash Identifiable Fields (for reversible matching)

If you need to link back to original data later:

You can store this hash as a reference key — the model sees only anonymised input.

3. Use Internal LLMs or Isolated Environments

For highly sensitive work (IP, legal, R&D), consider:

  • Running LLMs in a private cloud or on-prem
  • Using open-source models like LLaMA or Mistral inside firewalled environments
  • Wrapping models with policy enforcement, logging, and audit tools

4. Filter and Post-Process AI Output

Even if input is safe, the model can still generate unsafe responses. Use regex filters, classification models, or human review to scrub outputs before they’re exposed to users.

When This Matters Most

  • Legal: Leaking case files or privileged communications
  • Healthcare: Exposing patient info, violating healthcare codes
  • Finance: Sharing transaction history, insider data
  • Tech: Revealing product roadmaps, code, or strategies

Final Thought

LLMs don’t protect your data — they process what you give them. That means security and privacy need to be enforced before and after the model, not just inside it. With smart redaction, structured pipelines, and enterprise-grade access control, AI becomes powerful and safe.

Need help deploying AI without risking your IP? AndMine can help you design secure, scalable AI systems that protect your data and reputation.

Michael Simonetti, BSc BE MTE
Posted by:

Post Reads: 767

Share this

Go on, see if you can challenge us on "AI Security, Intellectual Property (IP) & Privacy Gaps – What is confidential to AI?" - Part of our 183 services at AndMine. We are quick to respond but if you want to go direct, test us during office hours.

Add Your Comment

Trusted by

The Age
PranaOn
Melbourne Sports and Aquatic Centre – MSAC
Thomson Geer
ABC
Toni&Guy
Maxine
Toy World
Van Egmond Group
King Wood Mallesons
nara logo
Movember
Peter Mac
kestrel logo
Amino Active
MyAccount
Australian Government
ADP Payroll
Magento Solution Specialist
Sports Power
Madman Entertainment
Dial Before You Dig
Cell Therapies
Windsorsmith
Switzer Media+Publishing
University of South Australia
Vendor Advocacy Australia
Scrum.org
Taylor Rose
Forbes
Inferflora
ATT logo
OJAY
Bulk Nutrients
Loan Market
Beaumont
Positive Poster
Plants
Launtel
Melbourne Heart
CB Richard Ellis
NGS Super
The Fortune Institute
Ego Pharmaceuticals
Oracle
aga logo
findstaff logo
Eway
Elucent
Atlantic Group of Companies
Ebay
ctc logo
Moov Head Lice
Associated Press
CCI
Uber
Engine Swim
CAN- Common Wealth Bank
Cronos Australia
The Royal Melbourne Hospital
ACTUATE IP
131 Pizza
Bondi Sands
OMS – Order Management System
Gilchrist Connell
Green St Juice CO
Hanover
Celebrate Health
Australian Organic Food CO
Sunday Creek
The Burger Cheese
BlackMores
Kadac
interact logo
Naturtint
Carlton Football Club
Drupal
Fairfax Media
Gadens
Google
Florsheim Shoes
McArthur Skincare
work and training logo
Chia
SMH – The Sydney Morning Herald
Macmillan Publishing
HGG 
Rackspace
Boston Consulting Group
Grow Your Business
NMI Insurance
News
Dinosaur Designs
Melbourne Central
liberal
Shell
Etihad Stadium
help logo
QV Skincare
21st Century Australia Party
RMIT University
Tribe
GPT Group
Australian Anthill
Passage Foods
htn logo
Melrose MCT
The University Of Melbourne
Metricon
Bigcommerce
Watches of Switzerland
NextTech
Bostik
Unsw Australia
Appstore
SunSense Digital Agency
Novvi
Paypal
Gilbert+Tobin
Royal Freemasons
Magento
French Tables
Tek Ocean
iPrimus
Victorian Government
Acquia Certified Site Builder Drupal
Grainshaker
Parker Lane
OpenAI
AC/DC
Cleanfit
Matchbox Homewares
White Suede
Mark Alexander Design
Grays Ecommerce
The Canberra Times
Mecca Brands
National Relay Services
itfe logo
James Buyer Advocates
High Street Armadale
Microsoft Certified Azure Fundamentals
SwinBurne University of Technology
National Museum of Australia
WTFN
ISO CERTIFIED 27001
ISO Certified
MAP
Telstra
Banki Haddock Fiora
DeeWhy Market
Hairhouse Warehouse
intowork logo
Ello
Jetstar
Arthur Galan
Viktoria & Woods
Rock Pool Group
skillhire logo
Crumpler
Natralus Australia
Max’s
Tomorrow Stars Basketball
Federation Square
Marshall White
Corrs chambers westgarth
Arc One
mas national logo
Cooper Mills
Oakdale Meat Co
Think & Grow Rich Inc
Bank of Cyprus
Catholic Insurance
Instant RockStar
Wild Rhino Shoes
Jalna
Castran Gilbert
Kay&Burton
Mamma Lucia
TPP
GooglePlay
VISSF
Australian Physiotherapy Association
Rydges
Globird
Palace Cinemas
Ubertas Group
Herbert Smith Freehills
Fresh Cheese Company
Adobe Professional
learning partners logo
Tassal
Passage To India
Aqium Gel
Heat Holders
Smart Company
Federation University Australia
Schiavello
DUSA, Deakin University Student Association
Engineers Without Borders
nextgenskills logo
Bolle Safety
LBG Australia and New Zealand
Fit My Car
POSTER Magazine
Craft CMS
Xavier
One Shift
Bintani Australia
Vitura Health
Fast.co
Melrose Health
Macpherson Kelley
Brisbane Times
Garmin
Street Kitchen
Coles
Focus On Furniture
intojobs logo

Testimonials

The &Mine team is great to work with and went beyond the brief to deliver a family violence website which was both engaging and easy to use. The team is collaborative, understand the constraints and sensitivities of a government environment and work alongside you to develop creative and practical solutions and ideas. Stakeholders have only had positive feedback about the website including with comments such as the best government website I have seen. Christine Panayotou, Director Communications, Family Safety Victoria

More Testimonials
AndMine-Google-Partner-Signature