← Concept IndexDEFINITION WHY IT MATTERS COMMONLY CONFUSED WITH SOURCES
Privacy and confidential information
Also called: don't paste secrets, data minimisation
The discipline of not putting personal, confidential, or regulated information into a tool unless you know where it goes, how long it's kept, and whether it trains a future model.
A prompt can be logged, retained, or reviewed. Once someone else's personal data is in a third-party tool, you may have broken a promise or a law on their behalf — so the default is to minimise and check first.
Security. Privacy is about whether the data should be there at all; security is about protecting it once it is.
- Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1U.S. National Institute of Standards and Technology · 2023-01-26
- Recommendation on the Ethics of Artificial IntelligenceUNESCO · 2021-11-23
First-pass citations, limited to primary sources; a reviewer will broaden and verify these before this entry leaves draft.