① Personal data such as resident registration numbers, credit card numbers, passwords, or sensitive information (e.g. biometric data, sexual orientation) shall not be entered into prompts. ② Where the analysis of personal data using generative AI is necessary, such data must be pseudonymized. ③ Confidential materials requiring a high level of security—depending on their security classification (e.g. victim interviews, non-public meeting minutes, accounting records)—shall not be uploaded via prompts. ④ The terms of service, privacy policy, and security policies of generative AI services shall be reviewed to understand data retention periods; whether prompt data are used for AI training; compliance with relevant laws such as data protection legislation; security measures such as encryption; and differences in security levels across pricing plans. Where possible, options or plans that allow users to opt out of training data use should be selected. ⑤ Data shared through generative AI services shall be regularly backed up and deleted. ⑥ When generative AI services are integrated with other applications or external APIs, the scope of data transmitted shall be reviewed to ensure that no unnecessary personal data or information are transferred. ⑦ Work-related accounts and personal accounts shall be used separately. 4) Copyright The use of generative AI entails copyright infringement risks in multiple respects. At the societal level, there is ongoing debate over whether AI companies may use copyrighted works as training data without the consent of rights holders, but this is largely beyond the control of individual users. Nevertheless, because personal data or copyrighted works used in training may be memorized by the model and reflected in its outputs, users may face copyright liability—even without intent—if generative AI produces outputs that are substantially similar to copyrighted works used in training. 44 45

Select target paragraph3