
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
Community Bank, operating in Pennsylvania, Ohio, and West Virginia, disclosed a data breach after an employee uploaded sensitive customer information—including names, birth dates, and Social Security numbers—to an unauthorized AI-based application. The incident exposed private data, prompting regulatory disclosure and customer notifications due to legal and privacy concerns.[AI generated]
Why's our monitor labelling this an incident or hazard?
The event explicitly mentions the use of an unauthorized AI-based software application that caused exposure of sensitive personal data, which is a violation of privacy and data protection rights. This meets the criteria for an AI Incident because the AI system's use directly led to harm (violation of rights and potential harm to individuals). The incident is not merely a potential risk but a realized harm, and thus it cannot be classified as a hazard or complementary information. It is not unrelated because the AI system's involvement is central to the incident.[AI generated]