Skip to main content

Freedom of information request

Data breaches and security incidents linked to AI chatbots

Freedom of information request reference
CAS-254772
Request resolved

Request

I am requesting a list and summary of any breaches in GDPR regulation of personal data, protection and usage; data losses; or other data security incidents caused by Generative AI chatbots reported to your department from 01/01/22 and the date this request is processed.

When referring to confidential or sensitive government information I am referring to any documentation or information placed into an AI Chatbot that was not intended or not cleared for publication.

I also note that when referring to Generative AI Chatbots I am referring to any software application that uses machine learning and natural language processing to interact with users through text or speech.

Please could I received the following:

  1. The number of times confidential or sensitive government information placed into an AI Chatbot has caused a data breach or cyber security incident between 01/01/22 and the day this request is processed.
    1. If possible, please include the nature of each incident, the number of individuals affected (if applicable), and any outcomes or remedial actions taken.
  2. The number of times personal or private information placed into an AI Chatbot has caused a breach in GDPR regulation between 01/01/22 and the day this request is processed.
    1. If possible, please include the nature of each incident, the number of individuals affected (if applicable), and any outcomes or remedial actions taken.
  3. Which AI Chatbot tool the departments allows civil servants and ministers to use, or if applicable any bespoke AI Chabot the department uses.

Outcome

Information not held.

Response

The National Archives has no record of any such data breaches or cyber-security incidents.
I can confirm that The National Archives does not currently use Chatbot tools.