Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The guidance explicitly says to log model inputs and outputs for drift monitoring, but provides no guardrails for sensitive data minimization, redaction, consent, retention, or access control. In an ML/AI system context, inference payloads often contain PII, confidential business data, prompts, uploaded documents, or model outputs derived from sensitive inputs, so following this advice naively can create a privacy and data-exposure risk.
