or external APIs, the scope of data transmitted shall be reviewed to ensure that no unnecessary personal data or information are transferred. ⑦ Work-related accounts and personal accounts shall be used separately. Data such as text entered into prompts by users or documents uploaded to generative AI services are transmitted to and stored on the servers of AI providers. In this process, various security threats may arise. Security breaches may occur during data transmission; AI providers may access stored data without authorization; or data may be leaked if the provider’s servers are compromised through hacking. The same security considerations that apply when storing an organization’s data on cloud services such as Google Drive are equally relevant in this context. * The Digital Justice Network (formerly Korean Progressive Network Jinbonet) published 〈2024 Digital Security Guide〉 and 〈Guide to Ensuring the Security of Personal Data〉 in 2024. For general security policies and data protection measures that civil society organizations should follow, please refer to these guides. There are additional security risks specific to generative AI. Data transmitted to an AI provider’s servers may later be used as training data in subsequent rounds of model retraining. Although generative AI systems do not store training data verbatim or directly reproduce it in their outputs, research has shown that certain 74 75

Select target paragraph3