① Personal data such as resident registration numbers, credit card
numbers, passwords, or sensitive information (e.g. biometric data,
sexual orientation) shall not be entered into prompts.
② Where the analysis of personal data using generative AI is necessary,
such data must be pseudonymized.
③ Confidential materials requiring a high level of security—depending on
their security classification (e.g. victim interviews, non-public meeting
minutes, accounting records)—shall not be uploaded via prompts.
④ The terms of service, privacy policy, and security policies of generative
AI services shall be reviewed to understand data retention periods;
whether prompt data are used for AI training; compliance with relevant
laws such as data protection legislation; security measures such as
encryption; and differences in security levels across pricing plans.
Where possible, options or plans that allow users to opt out of training
data use should be selected.
⑤ Data shared through generative AI services shall be regularly backed
up and deleted.
⑥ When generative AI services are integrated with other applications or
external APIs, the scope of data transmitted shall be reviewed to ensure
that no unnecessary personal data or information are transferred.
⑦ Work-related accounts and personal accounts shall be used separately.
4) Copyright
The use of generative AI entails copyright infringement risks in multiple
respects. At the societal level, there is ongoing debate over whether
AI companies may use copyrighted works as training data without the
consent of rights holders, but this is largely beyond the control of individual
users. Nevertheless, because personal data or copyrighted works used
in training may be memorized by the model and reflected in its outputs,
users may face copyright liability—even without intent—if generative AI
produces outputs that are substantially similar to copyrighted works used
in training.
44
45