Sensitive information disclosure
An AI system revealing personal, confidential or security data through its outputs, logs or tool calls.
Sensitive information disclosure is the risk that an AI system reveals personal data, confidential business information or security credentials through its outputs, its logs or the tools it calls, whether through error or manipulation. NIST's Generative AI Profile lists data privacy among the risks of generative AI, covering leakage, unauthorised use, disclosure or de-anonymisation of personal or sensitive information. For agents, the main defences are minimisation of the context each step receives, redaction in logs and strict separation of credentials from the model.
Agent Minute explains this term on 7 February 2027.
Related terms
Data minimisationUsing personal data that is adequate, relevant and limited to what is necessary for the purpose.Prompt injectionAn attack that alters what a model receives so that it follows the attacker's instructions instead of its user's.Access tokenA credential a client presents to access protected resources, representing a specific, limited authorisation.Personal dataAny information relating to an identified or identifiable living person.