DARR
MR-011 Data, privacy & content liability Both scope

Unlawful or non-consensual collection and processing of personal data

Personal data is collected or processed (e.g. via scraping, secondary use, or without consent) in violation of privacy law and expectations, as distinct from that data later leaking in outputs (MR-009).

Risk family
Data, privacy & content liability
MIT domain
2. Privacy & Security
MIT subdomain
2.1 > Compromise of privacy by leaking or correctly inferring sensitive information
AI type
GPAI, Classical_ML
Scope
Both
Source standard
MIT AI Risk Repository v4

Provenance

Source standard
MIT AI Risk Repository v4
MIT source entries
15 entries across 10 papers
  • Abercrombie2024A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms58.07.02
  • EPIC2023Generating Harms - Generative AI's impact and paths forwards31.03.00 31.03.01 31.03.02
  • Gabriel2024The Ethics of Advanced AI Assistants24.07.02
  • IBM2025AI Risk Atlas65.02.01 65.02.02 65.02.03
  • Kumar2023Ethical Issues in the Development of Artificial Intelligence: Recognizing the Risks38.01.00
  • Li2025A Closer Look at the Existing Risks of Generative AI: Mapping the Who, What, and How of Real-World Incidents66.09.01 66.09.04
  • Solaiman2023Evaluating the Social Impact of Generative AI Systems in Systems and Society13.01.04
  • TC2602024AI Safety Governance Framework45.01.07
  • Teixeira2022An Exploratory Diagnosis of Artificial Intelligence Risks for a Responsible Governance42.09.00
  • Weidinger2023Sociotechnical Safety Evaluation of Generative AI Systems18.05.04

Ev IDs of the entries consolidated into this risk in the MIT AI Risk Repository (V4); the source sheet row appears on hover.

ISO/IEC references
23894 obj A.8; src 6; mech B.5 | 42001 ctrl A.7.3, A.7.5
EU AI Act articles
Art. 10 | Art. 26(9)

Framework crosswalk

Every framework item mapped to this risk. Items marked partial overlap only in part; definitions appear on hover where the source licence permits.

Sourcesframeworks that contributed to the register
1
  • A.8 ISO/IEC 23894 Annex A A.8
2
  • A.7.3 ISO/IEC 42001 Annex A A.7.3
  • A.7.5 ISO/IEC 42001 Annex A A.7.5
2
  • Art. 10
  • Art. 26(9)
Cross-checksframeworks mapped in to test coverage
6
  • ibm-data-acquisition-restrictions Data acquisition restrictions partial
  • ibm-data-privacy-rights-alignment Data privacy rights alignment
  • ibm-data-transfer-restrictions Data transfer restrictions partial
  • ibm-data-usage-restrictions Data usage restrictions partial
  • ibm-personal-information-in-data Personal information in data
  • ibm-personal-information-in-prompt Personal information in prompt
1
  • GENAI.4 Data Privacy

Part of the Deployer AI Risk Register, an open-source resource powered by MindXO. Version 1.0, 3 July 2026. Derived from the MIT AI Risk Repository (V4, December 2025) under CC BY 4.0; an independent derivative work, not endorsed by or affiliated with MIT. Sub-risk decomposition references MITRE ATLAS™ v5.6.0 (© 2021-2026 The MITRE Corporation, reproduced and distributed with permission). ISO/IEC and EU AI Act references are by number only. License: CC BY 4.0. Full attribution and licensing.