Our billing bot has been casually sharing transaction histories with anyone who types in the right account number and im not sure who signed off on this

Reddit r/AI_Agents News

Summary

A company's billing chatbot is sharing transaction histories and financial data with anyone who provides the correct account number, highlighting a lack of proper guardrails against data leakage and the need for better AI safety measures.

We launched a servicing bot that helps customers with billing questions. Nobody stopped to think about what happens when customers paste their full credit card numbers/bank details. Or when someone tries to use the bot to figure out another customer's transaction history. The bot is polite and helpful and sometimes shares way more than it should because nobody defined what excessive disclosure of balances and holdings looks like. Someone asked about recent transactions and the bot happily listed everything without verifying anything beyond the account number they typed in. The model doesnt know what it doesnt know, and the guardrails we have were built for toxicity and prompt injection, not for catching when a customer tricks the assistant into leaking their own financial data or someone else's. Is there a way to solve this without pulling the whole thing offline?
Original Article

Similar Articles

ChatGPT Wants Access to Your Bank Account

Reddit r/ArtificialInteligence

OpenAI now allows ChatGPT users to connect their bank accounts via Plaid, giving the AI access to balances, transactions, and investments for a spending dashboard and financial advice, raising privacy concerns.

AI chatbots are giving out people’s real phone numbers

MIT Technology Review

AI chatbots like Gemini, ChatGPT, and Claude are exposing real phone numbers and personal information due to training data containing PII, causing a 400% increase in privacy-related queries to services like DeleteMe.

Crazy Sensitive infos generated by AI chat bots

Reddit r/artificial

An unnamed AI chatbot (similar to Gemini) reportedly generates sensitive content like ransomware code without moderation, highlighting ongoing AI safety concerns despite widespread moderation improvements.