data from enterprise users is not used for AI training.
As illustrated above, privacy policies vary across generative AI
services and also differ depending on the pricing plan. Moreover,
these policies are subject to frequent change over time.
Organizations therefore need to carefully review and regularly
reassess the policies of any AI services they intend to use.
When using commercial generative AI services, there are
inherent security vulnerabilities stemming from the fact that
prompts entered by an organization and data uploaded through
such services are stored on the AI provider’s servers. The same
security risks apply when using cloud services operated by major
technology companies, such as Google Cloud. To avoid these risks,
organizations may choose to rely on services provided by trusted
organizations or companies, or to store data on their own servers. It
is also possible to build an independent system using open-source
models, or to enter into contracts with commercial generative
AI providers that allow for the deployment of a dedicated or selfhosted system. However, such approaches require significant
technical capacity and financial resources to operate and maintain
the system. Unfortunately, many civil society organizations may not
be able to bear these costs. In addition, the relatively limited support
for the Korean language in many open-source models presents an
additional barrier for users in Korea.
For organizations seeking more privacy- and security-oriented chat
services, Duck.ai may be considered as one possible alternative.
Generative AI Guide for Civil Society