What Is AI Data Exfiltration?

AI data exfiltration is the unauthorized extraction of sensitive data through interactions with an AI system, either by an external attacker manipulating the model or by legitimate users inadvertently exposing data through normal use.

Why It Matters

AI systems create a new pathway for data loss that doesn’t require breaching a network or database directly, sensitive information can leave an organization simply because someone typed it into a prompt, or because an attacker manipulated a model into revealing data it had access to.

A Practical Example

An attacker crafts a series of prompts designed to get an AI customer service chatbot to reveal details from other customers’ support tickets that the model was given access to for context.

Related Terms

Need help governing AI risk like this across your organization?

Cyberix’s AI Security & Governance service finds, governs, and secures the AI already in use inside your organization.

See AI Security & Governance →