{"id":93650,"date":"2023-06-23T08:15:00","date_gmt":"2023-06-23T08:15:00","guid":{"rendered":"https:\/\/cloudnewshub.com\/?p=93650"},"modified":"2023-06-23T08:15:00","modified_gmt":"2023-06-23T08:15:00","slug":"generative-ai-data-privacy-backup-and-compliance","status":"publish","type":"post","link":"https:\/\/cloudnewshub.com\/?p=93650","title":{"rendered":"Generative AI: Data privacy, backup and compliance"},"content":{"rendered":"<div><img decoding=\"async\" src=\"http:\/\/cloudnewshub.com\/wp-content\/uploads\/2023\/06\/generative-ai-data-privacy-backup-and-compliance.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>Generative or conversational artificial intelligence (AI) tools have attracted a lot of attention, as well as some controversy, as applications such as OpenAI\u2019s <a href=\"https:\/\/www.techtarget.com\/whatis\/definition\/ChatGPT\">ChatGPT<\/a> and Google\u2019s Bard create human-like responses to queries or prompts.<\/p>\n<p>These apps draw on large databases of content and raise questions around intellectual property, privacy and security. In this article, we look at how chatbots work, the risks posed to <a href=\"https:\/\/www.computerweekly.com\/resources\/Data-protection-regulations-and-compliance\">data privacy and compliance<\/a>, and where generated content stands with regards to backup.<\/p>\n<p>These tools \u2013 more accurately termed \u201cgenerative AI\u201d \u2013 draw on large language models to create human-like responses (see box). OpenAI\u2019s large language model is the Generative Pre-trained Transformer (or GPT); Google Bard uses Language Model for Dialogue Applications (LaMDA).<\/p>\n<p>However, the rapid growth of these services has caused <a href=\"https:\/\/www.techtarget.com\/searchsecurity\/tip\/ChatGPT-security-risks-in-the-enterprise\">concern among IT professionals<\/a>. According to Mathieu Gorge, founder of VigiTrust, in a recent research project, all 15 chief information security officers he interviewed mentioned <a href=\"https:\/\/www.techtarget.com\/searchcio\/news\/365535293\/AI-rules-take-center-stage-amid-growing-ChatGPT-concerns\">generative AI as a worry<\/a>.<\/p>\n<p>\u201cThe most serious concerns are IP leakage and confidentiality when using generative AI,\u201d says Gorge, adding that the ease of use of web- or app-based AI tools risks creating another form of shadow IT.<\/p>\n<p>As online services, generative AI apps transmit and process data over the internet. The main services do not detail where they physically store data.<\/p>\n<p>\u201cEvery one of these services has different terms and conditions, and you need to read these very carefully,\u201d says Tony Lock at Freeform Dynamics. \u201cAre they using your inputs, so next time you log on they know who you are and how you like to phrase your queries? They are probably saving some of that information. A lot depends on the systems, because some use old data [to answer queries] and others go out and look at everything they can find.\u201d<\/p>\n<section class=\"section main-article-chapter\" data-menu-title=\"Chatbots and data privacy\">\n<h3 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"><\/i>Chatbots and data privacy<\/h3>\n<p>These services do have data privacy policies, however. ChatGPT, for example, allows users to delete conversations one at a time (within a 30 day limit), to delete all their data, or to delete their entire account.<\/p>\n<p>And the service monitors queries to prevent abuse. ChatGPT retains user data to improve its services, but users can opt out. Google, meanwhile, states that Bard collects \u201cconversations, your location, your feedback and usage information\u201d to improve the service and to improve Google\u2019s machine learning services. It does not, despite online rumour, access personal information in Gmail or other Google service accounts.<\/p>\n<p>Despite these safeguards, chatbot services pose a number of challenges for enterprises. They use public data for their models, but unlike enterprise-based machine learning and AI, firms have no control over or visibility into the training data. Nor is there any automated way to stop an employee sharing intellectual property or personally identifiable data, such as health or financial records, with Bard or ChatGPT.<\/p>\n<p>\u201cYou need to have a policy and rules for where and when you use it,\u201d says Gorge. Using a generative AI tool to create marketing materials is acceptable, he suggests, but they should not be used for sensitive and critical documents such as contracts.<\/p>\n<p>Also, you need to define where data will be held and what will be used in the model, says Richard Watson-Bruhn, data security expert at PA Consulting.<\/p>\n<p>\u201cYou may be using chat-like content in the model or you might be holding it separately for records,\u201d he says. \u201cChat GPT, for example, records previous chats and typically uses them to improve model outcomes. There might, however, also be important compliance reasons to hold chats on a temporary basis even if they aren\u2019t incorporated into the model.\u201d<\/p>\n<\/section>\n<section class=\"section main-article-chapter\" data-menu-title=\"Chatbots and compliance\">\n<h3 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"><\/i>Chatbots and compliance<\/h3>\n<p>The use of public chatbot services also raises a number of compliance questions. If firms want to use customer data with generative AI, they will need to ensure data processing complies with GDPR. For internally operated systems, it is possible to obtain these consents.<\/p>\n<p>For public chatbots, this is almost certainly impossible, prompting experts to advise against sharing personal data and even state bans.<\/p>\n<p>These have been seen in the&nbsp;<a href=\"https:\/\/www.techtarget.com\/searchcio\/news\/365535293\/AI-rules-take-center-stage-amid-growing-ChatGPT-concerns\">Italian DPA temporary ban for GDPR non-compliance<\/a>&nbsp;(now lifted) and incidents such as the&nbsp;<a href=\"https:\/\/www.techtarget.com\/searchenterpriseai\/feature\/ChatGPT-in-the-current-manufacturing-landscape\">security breaches Samsung suffered using the ChatGPT tool<\/a>.&nbsp;Heads of security and privacy are being drawn into considerations and questions on the business use, risks and compliance requirements of AI use.<\/p>\n<p>There is a further compliance issue if enterprises use generative AI to make decisions that affect customers. Regulators are looking more closely at decisions made by AI or machine learning systems, and they will want to see these are made on reasonable grounds and free of bias and discrimination.<\/p>\n<p>For in-house technology, keeping the records of decisions should be straightforward, and firms should also record details of the data used to train models. None of this is possible with public chatbots. Moreover, it is possible a generative AI system will make different decisions based on seemingly similar queries \u2013 the language models can interpret different words or phrases in different ways to a human analyst \u2013 and if training data or the large language model changes, this will also affect results.<\/p>\n<p>This makes it hard for firms to explain decisions made by generative AI systems and to justify them.<\/p>\n<p>\u201cOne of the issues is repeatability, or lack of repeatability,\u201d says Patrick Smith, field chief technology officer for Europe at Pure Storage. \u201cIf you put the same queries into one of these AI tools, will you get the same response? I suspect you won\u2019t if they are constantly updating their training data. If you look at the tools you can put into your own systems, then you can clearly lock down the training data at any given point.\u201d<\/p>\n<\/section>\n<section class=\"section main-article-chapter\" data-menu-title=\"Chatbots and backup\">\n<h3 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"><\/i>Chatbots and backup<\/h3>\n<p>This then raises the question of how organisations backup chatbot data, or whether that is possible at all. Services such as ChatGPT save queries for 30 days, and it is possible to export queries and responses. Once again, though, it is down to the individual using the service to do this \u2013 there are as yet no enterprise-level automated backup and compliance tools for what are largely experimental services \u2013 and there is no way to capture a snapshot of training data for any one query (see box).<\/p>\n<p>This suggests that, while CIOs and chief data officers will want to experiment with generative AI, the technology still has some way to go before it is mature enough for mainstream enterprise use.<\/p>\n<\/section>\n","protected":false},"excerpt":{"rendered":"<p>Generative or conversational artificial intelligence (AI) tools have attracted a lot of attention, as well as some controversy, as applications such as OpenAI\u2019s ChatGPT and Google\u2019s Bard create human-like responses to queries or prompts. These apps draw on large databases of content and raise questions around intellectual property, privacy and security. In this article, we [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":93651,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[533],"tags":[],"class_list":["post-93650","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-it"],"_links":{"self":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/93650","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=93650"}],"version-history":[{"count":0,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/93650\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/media\/93651"}],"wp:attachment":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=93650"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=93650"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=93650"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}