Caesar AI Atlas
Образование
2023-06-30Кейс #52

Рецензенты грантов загружали заявки в генеративный ИИ для подготовки отчётов, что, как утверждается, нарушало конфиденциальность

Описание инцидента

Рецензенты заявок на государственные гранты Австралии вводили работы заявителей в системы генеративного ИИ, такие как ChatGPT, для генерации оценочных отчётов, что, как утверждается, создавало проблемы конфиденциальности и безопасности.

Комплайенс-досье

Практическое управление корпоративными рисками и регламенты

Влияние на бизнес и риски МСБ

Academic reviewers copied highly proprietary, confidential research grant proposals containing trade secrets and patents into public ChatGPT to write reviews, breaching NDAs and triggering government investigations. The reviewers faced lawsuits, loss of funding, and severe professional sanctions, causing immediate organizational disruption. Regulatory Impact Alignment: AI grading algorithms, automated plagiarism detectors, and remote exam proctoring systems operate in high-risk sectors under EU AI Act Annex III. Educational institutions must provide a formal appeal path, safeguard student FERPA privacy rights, and ensure transparent algorithmic auditing.

Главный комплайенс-урок

Intellectual property must be actively safeguarded from unauthorized public AI entry by third-party reviewers. Firms must update NDAs with explicit AI bans, implement network tracking, and mandate whitelisted enterprise models. Compliance Audit Standards: For detailed verification audits, this case maps directly under FERPA Student Privacy Standards & EU AI Act Annex III (High-Risk Classification). Systems deploying similar AI features must maintain dynamic security logs and hold systematic compliance records.

Пошаговый план внедрения регламентов

  • 1Prohibit public AI in NDAs: Update non-disclosure agreements (NDAs) to include explicit clauses prohibiting the input of confidential files into public AI.
  • 2Network logs file tracking: Deploy automated network tracking to detect and block unauthorized file transfers to public generative domains.
  • 3Sandboxed whitelisted enterprise LLMs: Mandate the use of secure, whitelisted enterprise AI systems that guarantee local data hosting.
  • 4Endpoint device logs audits: Conduct regular audits of employee device logs to check for unauthorized generative tool installations.
  • 5Automated Appeal Channel: Establish an active, human-moderated student appeal queue to override false-positive plagiarism or cheating accusations.
  • 6Audit Trail Logging: Generate cryptographically signed, tamper-proof logs of all automated grading decisions for FERPA transparency.
  • 7Bias Evaluation Audits: Conduct quarterly demographic evaluations to ensure grading software does not discriminate against ESL students.

Комментарий эксперта по комплайенсу

Профессиональный комплаенс-анализ инцидента

Copying a client's trade secrets or patent filings into public ChatGPT is a direct breach of contract. Employees think they are just being efficient, but they are leaking core assets to public developers. NDAs must explicitly address public AI, and firms must secure their data perimeter. Shadow AI leaks represent a severe liability.

Терминология и нюансы глоссария ИИ

AI Compliance FAQ

Critical answers regarding AI compliance, auditing, and organizational risks

QHow did Australian grant reviewers breach NDAs using ChatGPT?

To quickly generate draft reviews, academic reviewers copied and pasted confidential research grant proposals (which contained proprietary patent details) directly into the public ChatGPT browser, exposing the data.

QWhy is uploading proprietary text to public AI models risky?

Public models save prompt data to retrain their neural networks. Pasted patents or business secrets enter OpenAI's public database, voiding copyright and trade secret protections.

QHow can financial and research firms secure client patents?

By updating NDAs with explicit clauses banning public LLMs, using secure enterprise API environments, and deploying network-level data loss prevention (DLP) tools.

Участники инцидента

Кто развернул систему

OpenAI

Кто разработал систему

OpenAI

Кто пострадал

администраторы исследовательских грантовзаявители на исследовательские гранты

Проверяемые источники (3)

Рекомендуемые похожие кейсы

EducationCase #8

University GRADE algorithm drops PhD applicant evaluations due to rating feedback bias

From the 2013 through 2019 admissions cycles, UT Austin’s Department of Computer Science used GRADE, a statistical machine-learning system trained on past admissions decisions, to score and organize PhD applications. Critics said the system could reproduce historical admissions inequities and reduce attention to lower-scored applicants, while UT Austin said human reviewers still evaluated each file and later discontinued the tool.

Изучить досье
EducationCase #9

Student tragedy following unverified high school AI-cheating detector accusation

A 16-year-old student in Greater Noida, India, reportedly died by suicide after being questioned by school authorities over suspected use of AI tools during a pre-board examination. The student's family alleges she was publicly reprimanded and mentally harassed following the incident, contributing to severe distress. School officials deny harassment and state disciplinary actions followed exam rules.

Изучить досье
EducationCase #10

Middle school students suspended for generating deepfake class photos via commercial AI

Five boys at The Friends' School in Hobart, Tasmania allegedly created purported AI-generated pornographic images using photos of female classmates, with parents saying 21 girls were identified as victims. The images were reportedly shared in a boys' group chat. Tasmania Police said no charges had been laid and the youths were being dealt with under the Youth Justice Act.

Изучить досье