Parity in Practice: The Defender's Duty to Ethically Use AI

AI ETHICS The first consideration is system architecture, or cloud-based versus “on-prem” deployment. Cloud-based AI services process data on the vendor’s servers, typically in shared infrastructure serving multiple customers. This approach reduces costs and technical complexity but requires trust in the vendor’s security practices. On-premises deployment, by contrast, runs AI models on hardware the organization controls, keeping data entirely within the defender’s environment. On-premises solutions offer maximum data control but require significant technical expertise and capital investment. Currently, a hybrid approach or carefully vetted cloud deployment will prove more practical than full on-premises infrastructure for most defenders. But even a hybrid approach requires careful attention to what file systems are (and whether the public internet is) accessible to the model. Systems with any on-premises access should only have access to those specific files or folders in the file system that have been affirmatively vetted for concerns around confidentiality, privilege, and relevance. Although the RAG-related privacy concerns addressed in the literature capture the “data leaving the building” problem (i.e., the risk that confidential information is transmitted to and processed by external systems), there is also a “data in the building” problem that arises when local or on-premises deployment concentrates sensitive information within the firm’s own infrastructure, creating new vectors for insider threat, unauthorized access, and inadequate data governance. The landscape continues evolving. Research suggests that some organizations are moving away from “cloud-first to strategic hybrid: cloud for elasticity, on-premises for consistency, and edge for immediacy.” 69 What seems prohibitively expensive today may become feasible within years. Defenders should monitor these developments and reassess their options periodically. Security guarantees warrant careful scrutiny. Defenders should examine (1) whether the vendor encrypts data in transit and at rest (i.e., information actively moving between systems — such as from an email on a laptop to a cloud-based storage system — versus information stored in a fixed location, like on a server, hard drive, or cloud database), (2) who can access stored data within the vendor’s organization, (3) what third-party service terms, acceptable use policies, data retention policies, and/or any other policies apply, (4) whether the vendor uses customer data for model training, (5) what audit and logging capabilities exist, and (6) how the vendor handles security incidents and breach notifications. Vendors marketing to legal customers should provide clear, written answers to these questions. Vague assurances or refusals to document security practices suggest inadequate protection. Business and contractual terms matter as well. When practical, defenders with the necessary resources should negotiate for terms prohibiting vendor use of submitted data for training or other purposes, requiring prompt data deletion upon request, indemnifying the defender against security breaches caused by vendor negligence, and specifying the jurisdiction and venue for any disputes. Larger organizations may have leverage to negotiate custom terms; smaller offices and solo practitioners may need to accept standard terms but should review them carefully before committing.

35

Parity in Practice: The Defender’s Duty to Ethically Use AI

Made with FlippingBook Online document maker