A senior financial analyst at a publicly traded company uses a free ChatGPT-style consumer AI tool (not approved by IT) to help draft a press release about an upcoming acquisition. She pastes the full acquisition terms, deal value, and target company name into the chat to get better phrasing suggestions. The company's IT security team discovers this through DLP monitoring.
A company's employees use a free consumer-tier AI writing assistant. An employee drafts a confidential merger announcement using the tool. What is the PRIMARY data privacy and business risk?
- A.B. The confidential merger details in the prompt may be retained by the provider and potentially used for model training, risking disclosure to competitors or the public
- B.A. The AI writing assistant may introduce grammatical errors into the announcement
- C.C. The employee is violating copyright law by using AI to draft official communications
- D.D. The writing assistant may generate inaccurate financial figures that are not caught before publication
Why A is correct
Free consumer AI writing tools often retain prompts and may use them to improve models or are subject to data breaches. Submitting confidential merger information (material non-public information) to a third-party service creates serious risks: unauthorized disclosure, regulatory violations (securities law), and competitive intelligence exposure. This is the canonical 'shadow AI' data governance failure. Options A, C, and D are secondary concerns.
Know someone studying for AI Security Fundamentals? Send them this one.