Skip to content
#generative ai Dataset Open access

Privacy and Security Risks in AI and Generative AI Systems: An Empirical Study of Practitioner Perceptions and Mitigation Practices in Brazil

Sep 2026 · Zenodo (CERN European Organization for Nuclear Research)

Abstract

Context: The widespread adoption of Artificial Intelligence (AI) and, more recently, Generative AI (GenAI) systems has intensified privacy and security concerns in organizational settings. Beyond technical vulnerabilities, risks increasingly emerge from socio-technical factors involving user behavior, organizational governance, regulatory uncertainty, and the evolving threat landscape enabled by AI-based attacks. Goal: This study aims to investigate privacy and security risks associated with the use of AI and GenAI systems, examining how these risks are perceived by practitioners, which mitigation strategies are adopted in practice, and what challenges limit their effectiveness in real-world organizational contexts. Method: We adopted a mixed-method research design combining a literature review with an empirical survey of 101 IT professionals working primarily in the Brazilian public sector. Quantitative data were analyzed using descriptive statistics to assess perceived risks, mitigation strategies, and challenges, while qualitative data from open-ended questions were analyzed using inductive coding to identify recurring themes and contextual factors. Results: The results show that practitioners perceive privacy and security risks as highly critical, with data leakage, legal non-compliance, lack of transparency, prompt injection attacks, and malicious misuse of AI-generated content being rated as important or very important by most respondents. Although mitigation strategies such as avoiding sensitive data, anonymization, organizational policies, training, and technical controls are widely adopted, their effectiveness is perceived as limited. Qualitative findings reveal that risks are strongly shaped by governance gaps, low organizational maturity, insufficient training, shadow AI usage, lack of vendor transparency, and increasing AI-enabled cyber threats. Conclusions : The findings indicate a significant gap between the adoption of mitigation strategies and practitioners’ confidence in their effectiveness. Privacy and security risks in AI and GenAI systems are inherently socio-technical and cannot be adequately addressed through technical controls alone. Effective risk management requires integrated approaches that combine technical safeguards with organizational governance, regulatory alignment, training, and cultural change to support trustworthy AI adoption.\end{abstract}

View source

Similar papers

#artificial intelligence Conference Open access Apr 2020

ECCOLA - a Method for Implementing Ethically Aligned AI Systems

The method, ECCOLA, is presented, which aims at making the high-level AI ethics principles more practical, making it possible for developers to more easily implement them in practice.

Ville Vakkuri, Kai-Kristian Kemell, P. Abrahamsson · 64 citations · ⚡6
#computer vision Review Apr 2024

AI-powered Code Review with LLMs: Early Results

The goal is to not only refine the accuracy of the LLM-based tool but also to underscore its potential in streamlining the software development lifecycle through proactive code improvement and education.

Z. Rasheed, Malik Abdul Sami, Muhammad Waseem et al. · 62 citations · ⚡3
#computer vision Open access Mar 2024

LLM-based agents for automating the enhancement of user story quality: An early report

The use of large language models to automatically improve the user story quality in Austrian Post Group IT agile teams is explored, with a reference model for an Autonomous LLM-based Agent System developed and implemented at the company.

Zheying Zhang, M. Rayhan, Tomas Herda et al. · 48 citations · ⚡4
#computer vision Review Mar 2024

System for systematic literature review using multiple AI agents: Concept and an empirical evaluation

This paper introduces a novel multi-AI-agent system designed to fully automate SLRs, and demonstrates how it substantially reduces the time and effort traditionally required for SLRs while maintaining comprehensiveness and precision.

Abdul Malik Sami, Z. Rasheed, Kai-Kristian Kemell et al. · 44 citations · ⚡2
#computer vision Feb 2024

Can Large Language Models Serve as Data Analysts? A Multi-Agent Assisted Approach for Qualitative Data Analysis

The proposed LLM-based multi-agent system automates qualitative data analysis process, creating opportunities for researchers and practitioners, and future improvements focus on enhancing multilingual performance and integrating continuous expert feedback.

Z. Rasheed, Muhammad Waseem, Aakash Ahmad et al. · 41 citations

Related blog posts

Microsoft Research Blog Oct 7, 2026

Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses

Training AI agents with reinforcement learning can be challenging because their tools, context, and decision-making are managed by complex frameworks. Agent Lightning connects existing agents to RL training, making it easier to improve them without rebuilding them. The post Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses appeared first on Microsoft Research.

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.