Computerweekly AI Developers Face Regulatory Pressure Over Data Privacy Compliance
Article Content
- •ICO mandates compliance with data protection laws for AI model developers.
- •Ten major AI firms have pledged to enhance transparency and data protection practices.
- •Research uncovered 12,000 live API keys in training data, highlighting security risks.
The UK's Information Commissioner's Office (ICO) has issued a report stating that AI model developers must comply with data protection laws when using personal data to train large language models (LLMs). The ICO found that many developers lack transparency regarding the data they use, which often includes sensitive personal information. Ten major AI firms, including Amazon and Google, have pledged to improve their data protection practices following the ICO's recommendations. The ICO emphasized that developers need to identify a lawful basis for processing personal data, provide meaningful transparency, and enable individuals to exercise their rights. Recent research revealed that approximately 12,000 live API keys and passwords were found in the training data of one AI model, DeepSeek, raising concerns about security vulnerabilities. The ICO is monitoring compliance and has launched a call for evidence to gather insights on managing data protection risks in AI.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Common questions
What are the ICO's main recommendations for AI developers?
Which companies are affected by the ICO's report?
What security risks were identified in the training data?
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Sets Oct. 11 Deadline for Patching Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after they were exploited by the China-linked group Flax Typhoon. Federal agencies must patch or retire the affected software by October 11, 2026. The vulnerabilities…