Generative AI is redefining how we create, analyze, and interact with content. As members of the McMaster University community, it’s essential to approach these innovations with an informed, critical perspective.
As of December 2023, the Office of the Privacy Commissioner of Canada has also released “Principles for Responsible, Trustworthy and Privacy-Protective Generative AI Tools.”
While McMaster University provides resources to understand and navigate the complexities of generative AI, the university does not endorse the use of any specific generative AI tool. There are many generative AI tools available, and each of them come with specific capabilities, considerations, risks and opportunities.
The McMaster’s Privacy Office and Ontario’s Information and Privacy Commissioner are valuable resources for further understanding and guidance on privacy and data security matters.
For any tools that include automated functions, including artificial intelligence, the university must conduct an Algorithmic Impact Assessment (AIA). An AIA is a risk assessment process that determines the impact level of an automated decision-making system on the risks of harm to individuals.
The privacy office is responsible for conducting the AIA process. To begin the process, complete the Early Privacy Risk Check form. To learn more about how the AIA is part of McMaster’s privacy risk assessment framework, find more details on the PIA website.
Review principles of using AI at McMaster
While specific tools will have unique privacy and security considerations, there are some broad risks associated with these tools to be aware of before you use them. In what follows you can review some of the privacy risks and considerations with using generative AI tools.
Generative AI models produce outputs based on the data they were trained on. If these tools access sensitive or personal information during training, there’s a risk that such data could be unintentionally reflected in the outputs. For example, a model trained on medical records might generate responses that resemble real patient details. To protect privacy and comply with data security policies, avoid using generative AI tools that train on user inputs.
Even if direct personal data isn’t fed into the AI, there’s a risk that the model can infer or deduce personal information from the patterns it has learned. This inferred data can sometimes be reverse-engineered to reveal details about individuals or the datasets the model was trained on.
Generative AI can produce incredibly realistic content. This ability, when misused, can lead to the creation of ‘deepfakes’ — highly convincing but entirely fabricated videos, images, or audio recordings. Such manipulated content can have serious implications, from spreading misinformation to impersonating individuals.
Like all digital tools, generative AI systems store, process, and sometimes transmit data. If not adequately secured, these channels can become vulnerable to breaches, unauthorized access, or cyberattacks.
Many generative AI tools function as ‘black boxes’, meaning their inner workings and decision-making processes aren’t transparent. This lack of clarity can make it challenging to pinpoint data handling practices, privacy measures, or potential biases embedded in the tool.
Some generative AI tools might integrate with third-party platforms or services, raising concerns about where the data flows, who has access, and the privacy protocols of these external entities.