data from enterprise users is not used for AI training. As illustrated above, privacy policies vary across generative AI services and also differ depending on the pricing plan. Moreover, these policies are subject to frequent change over time. Organizations therefore need to carefully review and regularly reassess the policies of any AI services they intend to use. When using commercial generative AI services, there are inherent security vulnerabilities stemming from the fact that prompts entered by an organization and data uploaded through such services are stored on the AI provider’s servers. The same security risks apply when using cloud services operated by major technology companies, such as Google Cloud. To avoid these risks, organizations may choose to rely on services provided by trusted organizations or companies, or to store data on their own servers. It is also possible to build an independent system using open-source models, or to enter into contracts with commercial generative AI providers that allow for the deployment of a dedicated or selfhosted system. However, such approaches require significant technical capacity and financial resources to operate and maintain the system. Unfortunately, many civil society organizations may not be able to bear these costs. In addition, the relatively limited support for the Korean language in many open-source models presents an additional barrier for users in Korea. For organizations seeking more privacy- and security-oriented chat services, Duck.ai may be considered as one possible alternative. Generative AI Guide for Civil Society

Select target paragraph3