Data Breach and Security Warnings Over DeepSeek AI Prompt International Bans

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Chinese AI startup DeepSeek’s R1 language model and mobile assistant suffered a data breach exposing chat logs, API keys and operational data. Taiwan’s cybersecurity agency and multiple governments tested and flagged high security and censorship risks, triggering bans on DeepSeek use in public agencies worldwide.[AI generated]

Why's our monitor labelling this an incident or hazard?

The article explicitly involves an AI system (DeepSeek-R1 large language model) whose development and use have directly led to significant economic harm (stock market value loss) and possible intellectual property rights violations (alleged data/model theft). These harms fall under the AI Incident definition categories (c) violations of intellectual property rights and (e) other significant harms where AI's role is pivotal. Although the article discusses potential future impacts and geopolitical concerns, the realized economic harm and ongoing investigation into data theft justify classification as an AI Incident rather than a hazard or complementary information.[AI generated]
AI principles
Privacy & data governanceRobustness & digital securityRespect of human rightsAccountabilitySafetyTransparency & explainabilityDemocracy & human autonomy

Industries
Government, security, and defenceDigital securityIT infrastructure and hostingConsumer services

Affected stakeholders
ConsumersBusiness

Harm types
Human or fundamental rightsReputationalEconomic/PropertyPublic interest

Severity
AI incident

Business function:
Citizen/customer service

AI system task:
Content generationInteraction support/chatbots


Articles about this incident or hazard

Thumbnail Image

优刻得宣布合作360集团,布局"DeepSeek一体机+大模型安全"-科技频道-和讯网

2025-03-28
和讯网
Why's our monitor labelling this an incident or hazard?
The event involves AI systems (large models and DeepSeek integrated machine) and their security measures. However, the article does not describe any realized harm or incident caused by AI systems, nor does it report any specific potential harm or hazard. Instead, it focuses on proactive security collaboration and development, which is a governance and technical response to AI safety concerns. Therefore, it qualifies as Complementary Information rather than an AI Incident or AI Hazard.
Thumbnail Image

中國AI灰天鵝DeepSeek暗襲要害!只花5%成本「抄」越算力障礙、趁熱催生R2模型

2025-03-28
Yahoo News (Taiwan)
Why's our monitor labelling this an incident or hazard?
The article explicitly involves an AI system (DeepSeek-R1 large language model) whose development and use have directly led to significant economic harm (stock market value loss) and possible intellectual property rights violations (alleged data/model theft). These harms fall under the AI Incident definition categories (c) violations of intellectual property rights and (e) other significant harms where AI's role is pivotal. Although the article discusses potential future impacts and geopolitical concerns, the realized economic harm and ongoing investigation into data theft justify classification as an AI Incident rather than a hazard or complementary information.
Thumbnail Image

2025-03-28
IT168
Why's our monitor labelling this an incident or hazard?
The article explicitly mentions an AI system (DeepSeek-R1 language model and its AI assistant application) and describes a concrete harm: a data breach exposing user chat records, logs, API keys, and operational data. This constitutes a violation of privacy and possibly other legal obligations protecting user rights, fitting the definition of harm category (c) under AI Incident. The breach is directly linked to the AI system's backend database vulnerability. Although the article also discusses market impacts and geopolitical concerns, the data breach is a realized harm caused by the AI system's malfunction or security failure. Hence, the event is best classified as an AI Incident.
Thumbnail Image

台數發部測定DeepSeek有極高資安風險 陸委會籲台灣民眾審慎評估 | deepseek | 資安院 | 台灣大紀元 | 大紀元

2025-03-26
The Epoch Times
Why's our monitor labelling this an incident or hazard?
The article explicitly involves an AI system (DeepSeek AI) and discusses its development and use, particularly its vulnerabilities and censorship mechanisms. The security risks and censorship could plausibly lead to harms such as violations of rights (e.g., freedom of expression) and harm to communities through information control or misinformation. Since no realized harm is reported but credible risks are identified and warnings issued, this qualifies as an AI Hazard rather than an AI Incident. The article is not merely general AI news or a product announcement; it focuses on the potential risks and government advisories, fitting the definition of an AI Hazard.
Thumbnail Image

中國AI灰天鵝DeepSeek暗襲要害!只花5%成本「抄」越算力障礙、趁熱催生R2模型

2025-03-28
數位時代
Why's our monitor labelling this an incident or hazard?
The article explicitly involves AI systems (large language models) and their development and use. It reports on suspicious unauthorized data access and possible plagiarism, which could constitute intellectual property rights violations, a form of AI harm. However, the article does not confirm that these violations have been legally established or that harm has materialized. The significant market impact is economic but not directly linked to harm categories like injury or rights violations. Therefore, the event represents a plausible risk of harm (intellectual property violation and market disruption) rather than a confirmed incident. Hence, it fits the definition of an AI Hazard rather than an AI Incident or Complementary Information.
Thumbnail Image

數發部測試認定DeepSeek有高資安風險 陸委會籲國人審慎評估使用

2025-03-26
蕃新聞
Why's our monitor labelling this an incident or hazard?
DeepSeek is an AI system (a generative AI model) whose use has been tested and found to pose high cybersecurity risks. The bans by multiple governments and the administrative orders restricting its use in public agencies indicate that harm or significant risk has materialized or is ongoing. The AI system's censorship mechanism aligned with Beijing's policies implies a violation of rights (freedom of information, pluralism). The cybersecurity risks and restrictions on use in critical government infrastructure also suggest disruption risks. These factors meet the criteria for an AI Incident, as the AI system's use has directly or indirectly led to harms including security risks and rights violations.
Thumbnail Image

DeepSeek加持 财富管理装上"AI大脑

2025-03-28
k.sina.com.cn
Why's our monitor labelling this an incident or hazard?
The article explicitly involves an AI system (DeepSeek) used in financial advisory and wealth management, indicating AI system involvement. However, it does not describe any direct or indirect harm caused by the AI system, nor does it report any incident or malfunction leading to injury, rights violations, or other harms. The concerns about hallucinations and data privacy are noted as challenges and risks but are not linked to any realized harm. The article mainly provides information on AI adoption, applications, and governance responses in the financial industry, fitting the definition of Complementary Information rather than an Incident or Hazard.