How AI governance and data privacy go hand in hand

Aug 10, 2022 | Privacy

SOURCE: TechTarget

960px-Artificial_Neural_Network_with_Chip_4b32b63c5c28c858e051e9d1a2a717a1

Data protection and safeguarding user privacy are both key to regulations such as the Health Insurance Portability and Accountability Act, the California Consumer Privacy Act, the General Data Protection Regulation and the Biometric Information Privacy Act. Within the realm of AI governance, ensuring data privacy is just as practical and important.

This form of risk management is not just for regulatory compliance but also for protecting against potential reputational harms to your brand if data privacy norms are not met. To ensure data privacy, an organization can use an enterprise AI governance framework that defines regulatory compliance requirements and incorporates appropriate controls for risk management.

Challenges to achieving data privacy exist within AI governance

It’s a truism that data is at the heart of AI. Similarly, it’s also becoming clear that data governance is at the core of AI governance. No doubt, there appears to be an inherent tension between mining user data for actionable insights and preserving privacy, which is referred to as the utility-privacy tradeoff. But it’s also possible to strike a balance between utility and privacy.

It’s the stated goal for many organizations to be data driven. Organizations want to open their data and analytics applications more widely and empower their employees. However, this goal of data democratization is not widely realized in practice because of data protection and data privacy concerns. Many data sets contain users’ personal data and organizations worry that if data is more widely shared, there’s a greater chance of personally identifiable information leakage or attack vectors.

To prevent violations of privacy regulations and requirements, access to such data is typically restricted to teams such as IT or analytics. In other words, data privacy fears are hindering data democratization. Because of these concerns, such data sets are not made available to the machine learning teams for training AI models. This can potentially reduce the efficacy and usefulness of those AI models and applications.

How AI and data privacy can coexist within a framework

A privacy-by-design approach helps overcome these limitations, as AI and data privacy can then coexist as two parts of the AI lifecycle. Essential to this approach is using data anonymization techniques that preserve privacy without losing data’s usefulness in AI applications.

-De-identification. Here, personal identifiers and sensitive attributes are masked with non-sensitive placeholder values. The masking rules can range from simple, such as hiding the first few digits of a social security number or credit card and showing only the last few, to complex, such as using random tokenization to replace an original value with a seemingly unrelated string.

-K-anonymization. Here, individual privacy is protected by pooling the data that identifies an individual into a set of data where everyone has similar attributes. This technique can also be referred to as “hiding in the crowd” so that no record can be uniquely linked to an individual. For example, an individual’s age or income is replaced with an age or income bracket. Sometimes, certain attributes may be even dropped.

-Differential privacy. It is possible to infer what the inputs to an AI model are by analyzing its outputs. This technique is aimed to curb data leaks. This is done by adding “noise” (in the form of synthetic data) to the data set without losing the “signals” (i.e., useful predictive characteristics) in the data. Differential privacy techniques can be employed when privacy requirements are higher and data is more sensitive. There are several data governance tools that help implement differential privacy.

-Federated machine learning. Here, model training happens iteratively using different decentralized devices instead of centralized aggregation of data. This is not an anonymization technique per se, but it helps improve privacy.

Businesses have several techniques at their disposal to help improve AI and data privacy practices. In addition to data privacy protection in the context of AI governance, prudence is warranted throughout the entire data supply chain — from data collection and storage to processing, access and sharing. Therefore, IT/engineering, business and legal teams all have roles to play here as well.

Top 10 Cybersecurity Stories This Week: Brevo Supply Chain Attack Serves Malware to 100,000+ Websites via Stolen CDN API Key, Revolut Discloses Breach via Fake Government Requests, Gyazo 23.6 Million User Records Stolen

Top 10 Cybersecurity Stories This Week: Brevo Supply Chain Attack Serves Malware to 100,000+ Websites via Stolen CDN API Key, Revolut Discloses Breach via Fake Government Requests, Gyazo 23.6 Million User Records Stolen

September 25, 2026 | ITBriefcase.net Why it matters: Attackers compromised Brevo — the email marketing and CRM platform used by eBay, Louis Vuitton, Michelin, Amnesty International, and more than 100,000 other businesses — by exploiting a hardcoded, long-lived...

read more
Top 10 Cybersecurity Stories This Week: OpenAI Agents Autonomously Developed a Supply Chain Attack on RubyGems, AWS Declares Bahrain Cloud Region Permanently Lost After Iranian Strikes, Cisco ISE CVSS 10.0 Auth Bypass Under Active Exploitation

Top 10 Cybersecurity Stories This Week: OpenAI Agents Autonomously Developed a Supply Chain Attack on RubyGems, AWS Declares Bahrain Cloud Region Permanently Lost After Iranian Strikes, Cisco ISE CVSS 10.0 Auth Bypass Under Active Exploitation

September 18, 2026 | ITBriefcase.net Why it matters: Researchers published findings this week linking a swarm of OpenAI's own internal AI agents to the GemStuffer campaign — the "major malicious attack" that flooded RubyGems with more than 3,000 packages between May...

read more
Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

September 11, 2026 | ITBriefcase.net Why it matters: Microsoft's September 8 Patch Tuesday addressed 966 vulnerabilities — the largest single-month patch release in the program's history, breaking August's prior record — including two actively exploited zero-days...

read more
Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

September 4, 2026 | ITBriefcase.net Why it matters: ShinyHunters claimed responsibility for a breach of McKesson Corporation — the largest pharmaceutical distributor in North America, delivering approximately one-third of all prescription medicines to US hospitals,...

read more
Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

August 28, 2026 | ITBriefcase.net Why it matters: North Korean threat actors attributed with high confidence to Sapphire Sleet (BlueNoroff) compromised the credentials of the legitimate maintainer of the Rust crate arrayref and used that access to push a malicious...

read more
Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

August 21, 2026 | ITBriefcase.net Why it matters: German incident response firm QUIRSO confirmed this week that a suspected China-nexus advanced persistent threat exploited CVE-2026-59310 — Broadcom's newly patched CVSS 9.8 VMware vCenter directory traversal — just...

read more