Third-Party Data Exposure
Privacy & Data RiskDescription
Agent transmits sensitive business, personal, or regulated data to external tool providers, APIs, or services without data handling agreements or user consent. 'Shadow data sharing' through agent tool calls.
Agent processing HIPAA-covered health records sends patient data to an unvetted analytics API as part of a summarisation call.
Italy's Garante temporarily banned ChatGPT in March 2023 citing the inability of individuals to access, correct, or delete personal information held in the model, and the Irish Data Protection Commission opened formal investigations on the same grounds, confirming this as a realized regulatory and operational failure.
Primary mitigations
- Data classification before tool transmission
- egress monitoring for sensitive data
- tool data handling agreements
- privacy-preserving tool architectures.
Detection signals
Sensitive data egress rate in tool calls; regulatory data residency compliance.