Search the Atlas

Search risks, controls, and glossary terms

HighAgenticConfidential Data Shared with ToolsRealized

Third-Party Data Exposure

Privacy & Data Risk

Description

Agent transmits sensitive business, personal, or regulated data to external tool providers, APIs, or services without data handling agreements or user consent. 'Shadow data sharing' through agent tool calls.

Example scenario

Agent processing HIPAA-covered health records sends patient data to an unvetted analytics API as part of a summarisation call.

Real-world evidenceRealized

Italy's Garante temporarily banned ChatGPT in March 2023 citing the inability of individuals to access, correct, or delete personal information held in the model, and the Irish Data Protection Commission opened formal investigations on the same grounds, confirming this as a realized regulatory and operational failure.

Primary mitigations

  • Data classification before tool transmission
  • egress monitoring for sensitive data
  • tool data handling agreements
  • privacy-preserving tool architectures.

Detection signals

Sensitive data egress rate in tool calls; regulatory data residency compliance.

Mitigating controls

7
Dual coverage

Related risks in Privacy & Data Risk