Skip to content
Adrythm
AI and automation

Privacy-enhanced AI

private AI / AI data privacy / will my data train the model / trustworthy AI

In short

Privacy-enhanced AI means an AI system built so your data is not exposed or quietly reused. NIST lists it as one of seven characteristics of trustworthy AI, and states the honest catch: privacy techniques can cost accuracy. The FTC has required firms to delete models built on unlawfully obtained data.

Every AI tool pitched to a business raises the same question before any other: what happens to the information we put into it. Two government sources answer different halves of that, and neither is selling anything.

NIST places privacy in a list. Its AI Risk Management Framework names seven characteristics of trustworthy AI systems: valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed. Privacy is one of the seven. NIST says privacy values such as anonymity, confidentiality and control should guide how an AI system is designed, developed and deployed.

It also says something vendors rarely volunteer. Under certain conditions such as sparse data, privacy-enhancing techniques can result in a loss in accuracy. Privacy is a trade, not a free upgrade. NIST notes it can pull against other characteristics including security and bias. Anyone offering more privacy at no cost is describing a product nobody has built.

There is a second risk NIST names that is easy to miss. AI systems can present new privacy risks by allowing inference to identify individuals, or previously private information about them. The exposure is not only the data you hand over. It can be what the system works out.

The Federal Trade Commission covers what happens when a promise is broken. It warns that companies selling access to models have a continuous appetite for data. That incentive can sit at odds with their obligation to protect it. Its position is direct. Firms that fail to abide by their privacy commitments may be liable. That includes a promise not to use customer data for secret purposes such as training or updating their models, whether directly or through workarounds.

In practice

The consequence is heavier than a fine. The FTC says that in prior enforcement actions it has required businesses that unlawfully obtained consumer data to delete any products built with it. Models and algorithms included. A vendor can be ordered to destroy the thing you are paying to use. Worth knowing before a tool becomes load bearing in your business.

Not the same as

Encryption
That protects data in transit and at rest. This is about what the system is permitted to learn and retain.
A privacy policy
A document states an intention. NIST is describing design choices, and the FTC is describing enforcement.

Why it matters to you

Your customer records, your quotes and your internal documents are the material people paste into these tools. The question to ask is narrow and answerable: is our data used to train or update the model, is that in writing, and what happens to it when we leave. A vendor that cannot answer in a sentence has told you something.

What to ask or check

  1. 01Is our data used to train or improve the model, and where is that stated?
  2. 02Which of the seven NIST characteristics has this vendor actually addressed?
  3. 03If we stop using this tool, what happens to the data already sent?

What people get wrong

That privacy is a free upgrade. NIST states that under conditions such as sparse data, privacy-enhancing techniques can result in a loss in accuracy, and that privacy can pull against security and bias.

Red flags

  • A vendor that cannot say in writing whether your data trains or updates its model.
  • More privacy promised at no cost to accuracy, which NIST describes as a trade rather than an upgrade.
  • No answer on what happens to data already sent once you stop using the tool.

Who owns it

Worth settling in writing before a tool matters. The FTC treats a broken privacy commitment as its own problem regardless of where the promise was made.

AI Overviews

An AI Overview is the summary Google sometimes places above the results, with links to sources. Google says they are only shown when its systems judge them additive to classic Search, so they often do not trigger. There is no special file or markup that gets you into them.

Training data

Training data is what a model learned from. The question owners ask is whether their own data joins it, and there is no single answer: OWASP names three separate stages, pre-training, fine-tuning and embedding. A commitment worth having names the stage and comes in writing.

Retrieval augmented generation

Retrieval augmented generation is how an AI answers from your documents without being trained on them. OWASP describes it as combining a pre-trained model with external knowledge sources at answer time. So the documents sit in a store the system reads from, and who can read that store is the question.

AI agent

An AI agent is a model that has been granted the ability to take actions, not just produce text. OWASP says the damage one can do comes from three grants: excessive functionality, excessive permissions and excessive autonomy. What it is allowed to do matters more than how good it is.

Hallucination

A hallucination is AI output that sounds right and is not. OWASP describes the model filling gaps in its training data using statistical patterns, without understanding the content, so the answer can be fluent and unfounded at once. Its own first example is an airline that was successfully sued over its chatbot.

Prompt injection

Prompt injection is when text an AI system reads becomes an instruction it follows. OWASP notes the text does not have to be visible to a person, only parsed by the model, and that no fool-proof prevention is known. The UK's national cyber security body says the same.

Want this explained against your own numbers?

Twenty minutes, a straight answer, and no follow-up sequence if you decide not to work with us.