Submit incident

AI data exposure incidents

Definition

Data exposure incidents involve confidential, personal, proprietary or otherwise sensitive information being unintentionally disclosed, leaked or made accessible as a result of an AI system's operation, misuse, or the practices of parties that deploy or interact with AI systems.

Included

  • Confidential material entered into third-party AI systems and retained or used in training
  • Outputs from AI systems that inadvertently reveal personal data
  • AI-enabled data scraping or aggregation that exposes protected information
  • Leaks of training data containing personal, proprietary or sensitive records
  • Breaches of AI platforms that expose user conversation histories or query logs

Excluded

  • Breaches where AI played no material role in the exposure
  • Intentional sharing of data by the subject themselves
  • Theoretical risk assessments without a documented event
  • Incidents classified primarily under a different category where data exposure was incidental
Data exposure incidents over time
Documented incidents per year of occurrence. *2026 to date.
Timeline chart: requires category field in dataset (planned)
Unit: incidents · Source: AI Incident Index v2026.09 · Counts reflect documented incidents, not prevalence

Incident records3

Oct 2025China's Ministry of Industry Flags 20 Smart Devices for Privacy FailuresOECDSep 2024Three Seconds of Audio Is All It Takes to Steal Your VoiceOECDJan 2019Nineteen Privacy Groups Told the FTC That Alexa Couldn't Forget a ChildAIAAIC
Browse all incidents →