OpenAI announces a system to monitor AI abuses without retaining customer data. A key question for banks, hospitals, and universities. Imagine a hospital in Libreville wants to use AI (artificial intelligence) to summarize patient records before a medical meeting. Obvious time-saving. But a concern blocks the project: will the health data sent to the tool remain stored with...
Imagine a hospital in Libreville wants to use AI (artificial intelligence) to summarize patient records before a medical meeting. Obvious time-saving. But a concern blocks the project: will the health data sent to the tool remain stored with the provider? Who will be able to consult them?
The same question arises in a bank analyzing customer complaints, an administration processing social requests, or a university responding to its students. AI can help, but only if the organization knows precisely what it shares, with whom, and for how long.
When a company uses generative AI, it sends a prompt and receives a response: summary, analysis, draft letter, information extraction. The risk arises when this prompt contains sensitive data, such as a medical record, a payslip, or a customer complaint. OpenAI claims that its Private Safety Processing system can detect patterns of dangerous use across multiple exchanges, without giving OpenAI employees access to detailed content. The main challenge is therefore the balance between security and privacy. Good news: an organization can significantly reduce risks if it chooses the right contract, limits the data transmitted, and maintains human validation.
Concrete case: what to do and what not to do
Questions to Ask Before Acting
Do the data sent to the AI contain personal, medical, financial, or HR (human resources) information?
Does the provider keep the instructions and responses? If so, for how long?
Can the data be used to train or improve the model, unless explicitly agreed?
Does the contract provide for deletion, auditing, encryption, and precise access management?
Do the data remain in a geographically acceptable area for your organization?
Who validates the response before it is sent to a client, patient, student, or citizen?
What procedure do we follow in case of an error, leak, fabricated response, or unauthorized use?
By clicking on "Accept All", you authorize the placement of cookies to facilitate navigation, measure audience, and provide you with information about our training programs. Privacy policy
UNIVGA Group
Set cookies
Necessary cookies remain active. Other categories are optional. Learn more
NecessarySession, security, connection.
PreferencesLanguage and display.
AudienceVisitor statistics.
ProspectingInformation about our training programs.
We detected that you may prefer English. Would you like to switch?