
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
A RIZAP employee in Japan mistakenly uploaded sensitive customer data, including names, health conditions, and insurance numbers, to an external generative AI service during data processing. Although the data was deleted quickly and not used for AI training, the incident constitutes a privacy breach. RIZAP has apologized and reported the incident to authorities.[AI generated]
Why's our monitor labelling this an incident or hazard?
The event involves the use of a generative AI system to which sensitive personal data was mistakenly uploaded, constituting a misuse of the AI system. The incident has led to a violation of data protection obligations and potential privacy breaches, which are harms under the definition of AI Incident (violation of human rights or breach of applicable law). Although the AI system did not use the data for training, the unauthorized exposure and potential access by AI service personnel represent realized harm. Therefore, this qualifies as an AI Incident rather than a hazard or complementary information.[AI generated]