AI risks and data exposure to training are considered in privacy assessments of new and existing suppliers.
Baseline
Applies to every organization that uses AI, regardless of size or sector.
Why
AI functionality is regularly added to existing products and platforms, which remain covered by the existing processing agreements. Often no reassessment is triggered, and organizational data may then be processed by an AI model or used to train it. Processing agreements and privacy statements are subject to change.
How
Privacy assessments of existing and new suppliers should include whether organizational data may be used as training data for AI models. Known risks inherent to LLM's and other AI systems (see GV.4), such as incorrect output and access inherited from users (see AC.1), should also be considered when AI functionality is added to existing software.
Sources
- NIST AI RMF GOVERN 6.1
- NIST AI RMF MANAGE 3.1
- ISO/IEC 42001 A.10.3