---
term: "Sensitive information disclosure"
category: "AI risks and safety"
url: https://agenticopenfinance.com/glossary/sensitive-data-leakage
source: AgenticOpenFinance glossary
---

# Sensitive information disclosure

> An AI system revealing personal, confidential or security data through its outputs, logs or tool calls.

Sensitive information disclosure is the risk that an AI system reveals personal data, confidential business information or security credentials through its outputs, its logs or the tools it calls, whether through error or manipulation. NIST's Generative AI Profile lists data privacy among the risks of generative AI, covering leakage, unauthorised use, disclosure or de-anonymisation of personal or sensitive information. For agents, the main defences are minimisation of the context each step receives, redaction in logs and strict separation of credentials from the model.

Related terms: [Data minimisation](https://agenticopenfinance.com/glossary/data-minimisation.md), [Prompt injection](https://agenticopenfinance.com/glossary/prompt-injection.md), [Access token](https://agenticopenfinance.com/glossary/access-token.md), [Personal data](https://agenticopenfinance.com/glossary/personal-data.md)
