S0114RS3-T06-S0114-Z · Full risk code

Confidential Information Inadvertently Disclosed in Prompts

提示內容無意洩露機密

Operation & Monitoring
Risk Description

When for efficiency, an employee pastes a document containing customer data into an external tool for summarization; due to unmitigated control gaps, the content enters the provider's logging system, rendering the organization's security policy ineffective, triggering external stakeholder impacts and causing the issue is discovered only through a later audit, requiring customer notification and assessment of reporting obligations.

Framework Mappings

OWASP Top 10 for LLMLLM02
NIST AI 600-1Data Privacy
MITRE ATLASAML.T0057
ISO/IEC 5338運作與監控
MIT AI Risk RepositoryDomain 2

Risk Treatment & Implementation Guidance

Deploy a sensitive-information filtering gateway at the egress to external tools, detecting and blocking inputs containing customer data; Educate staff on the AI use policy, clearly delimiting what may enter external tools; Provide compliant internal alternatives to reduce the incentive to use external services