up and delete previously shared data. Of course, even if deletion
is requested, the data may not be immediately removed from the
AI provider’s servers and could be retained for a certain period of
time (for example, around 30 days). Nevertheless, deleting data
can still help reduce security risks. At the same time, it should be
taken into account that generative AI systems may refer to prior
conversation history when generating responses. Deleting past
data may therefore limit the usefulness or continuity of the service.
Keeping records of deletion schedules and clearly designating
responsible persons can be helpful for long-term data management
and accountability.
Sixth, when generative AI is integrated with other applications or
external APIs, it is necessary to verify the scope of the connected
applications and the data being transmitted, in order to ensure that
the generative AI does not access data beyond what is necessary or
transmit data to third parties unnecessarily. For example, ChatGPT’s
GPT Explore and plugin features may be integrated with external
services such as Expedia for travel planning or Canva for imagerelated tasks. In such cases, portions of the input provided within
ChatGPT may be transmitted to external providers like Expedia or
Canva, and this data may include personal information. Similarly,
Google Gemini can be integrated with other Google services such
as Gmail, Calendar, and Google Docs, and may also rely on external
services for functions such as flight or hotel searches.
In these situations, it is often difficult for users to clearly identify
which parts of the prompts they enter or the data they upload
are being shared with external providers. Furthermore, when
Generative AI Guide for Civil Society